Defense in Depth: Recent Episodes

David Spark

Defense in Depth promises clear talk on cybersecurity’s most controversial and confusing debates. Once a week we choose one controversial and popular cybersecurity debate and use the InfoSec community’s insights to lead our discussion.

View Details

All links and images can be found on CISO Series

Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Dan Walsh, CISO, Datavant. Joining is our sponsored guest, Elizabeth Nammour, founder and CEO, Teleskope.

In this episode:

  • Data ownership before automation
  • A shared vocabulary for agent risk
  • Maturing from crawl to run
  • Trust earns automation its place

A huge thanks to our sponsor, Teleskope

Most DSPMs stop at finding the risk. Teleskope fixes this: it automatically finds sensitive data, including IP documents or board decks, and remediates exposure across cloud, SaaS, and AI environments natively, with human-in-the-loop controls, improving your team's efficiency tenfold. Trusted by Ramp, Polymarket, and Chevron Phillips, and more. teleskope.ai

View Details

All links and images can be found on CISO Series

Prevention in cybersecurity is a lot like flossing: everyone knows they should do it, but few do it enough. What's stopping us?

Check out this post by Ross Haleliuk of Venture in Security for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Deneen DeFiore, vice president & chief information security officer, United Airlines.

In this episode:

  • The sponsorship gap
  • One strike and you're out
  • Policy without position
  • Prevention isn't static

A huge thanks to our sponsor, CoreView

Attackers don't break into Microsoft 365. They log in and reconfigure it. When tenant configurations drift or get tampered with, recovery can take weeks and missed settings can reopen the door. The Cyber Resilience Framework for Microsoft 365 covers the five pillars, harden, govern, detect, respond, recover, and shows exactly where today's tools leave gaps. Download the free practical guide

View Details

All links and images can be found on CISO Series

Check out this post by Tomás Maldonado, CISO, NFL, for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Yaron Levi, CISO, Dolby. Joining is Will Gregorian, vp of information technology & security, Galileo Medical.

In this episode:

  • From who to what
  • The manipulation problem
  • Cryptographic accountability
  • The audit gap

A huge thanks to our sponsor, ActiveState

ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time. Learn more at ActiveState.com.

View Details

All links and images can be found on CISO Series

Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining is their sponsored guest, Rajan Kapoor, vp, security, Material Security.

In this episode:

  • Pre-existing conditions
  • Architecture over rollout
  • Access isn't legitimacy
  • Data has a half-life

A huge thanks to our sponsor, Material Security

Legacy email security only watches the door. Material protects your entire cloud workspace—email, files, and accounts—as one ecosystem. It's more coverage for less than the cost of a legacy SEG. One price, no surprises: just security that covers the whole surface area. Learn more at material.security.

View Details

All links and images can be found on CISO Series

We're evolving fast to secure AI. But are we evolving fast enough to secure WITH AI?

Check out this post by Rinki Sethi, CSO, Upwind Security, for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Howard Holton, former CEO, GigaOm. Joining is Adam Glick, CSO, PSG Equity.

In this episode:

  • Human-in-the-loop math
  • Should machines decide at all
  • From assistant to autonomous
  • Redefining the security role

A huge thanks to our sponsor, Palo Alto Networks

Cortex Cloud unifies code, cloud, and SOC on a single data, risk, and control plane — giving teams the context, workflows, and agentic intelligence to turn risk into resolution. Native AI agents investigate and act within enterprise guardrails, delivering real-time protection from workload to network edge. Cloud security that outpaces machine-speed threats. Visit paloaltonetworks.com/cortex/cloud.

View Details

All links and images can be found on CISO Series

There are thousands of cybersecurity vendors across categories. If there's a gap in the market, it's likely not for technical reasons. So, how do you actually find vendors that are a good fit rather than one that just meets technical requirements?

Check out this post by Joe Head of REFLEX Solutions for the discussion that is the basis of our conversation on this week's episode, co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Ajit Girn, CIO, Employment Development Department (EDD).

In this episode:

  • Built for vendors, not users
  • Signal versus noise
  • Priced out
  • The elegance gap

A huge thanks to our sponsor, ThreatLocker

ThreatLocker takes a deny-by-default approach to endpoint security — controlling what applications can run, what can access data, and what can elevate privileges. Used by organizations that want to reduce attack surface without relying on detection alone. Learn more at threatlocker.com/ciso.

View Details

All links and images can be found on CISO Series

Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and George Finney, CISO, University of Texas System. Joining is Sean Walls, CISO, Bob's Discount Furniture.

In this episode:

  • Asymmetric accounting
  • Sometimes it really is that easy
  • The spirit of the saying
  • The cheapest way in

A huge thanks to our sponsor, Native Security

Native is the Cloud Security Control Plane. It helps enterprises enforce secure-by-design architecture across multi-cloud environments by translating security intent into the cloud provider's built-in controls, previewing impact before rollout, and keeping enforcement aligned as the environment changes.

View Details

What It Takes To Be Successful in Cyber Media

All links and images can be found on CISO Series

Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Dave Bittner, producer and host, The CyberWire. Joining is Graham Cluley, host of Smashing Security podcast and Leo Laporte, founder of TWiT (This Week in Tech) and host of Security Now podcast.

In this episode:

  • Format follows function
  • The decision gap
  • Practitioner fingerprints
  • Beyond the news cycle

A huge thanks to our sponsor, Palo Alto Networks

Cortex Cloud unifies code, cloud, and SOC on a single data, risk, and control plane — giving teams the context, workflows, and agentic intelligence to turn risk into resolution. Native AI agents investigate and act within enterprise guardrails, delivering real-time protection from workload to network edge. Cloud security that outpaces machine-speed threats. Learn more at paloaltonetworks.com/cortex/cloud/demo.

View Details

All links and images can be found on CISO Series

Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Howard Holton, CEO, GigaOm. Joining is Tyler King, senior director - threat operations and response, Sinclair.

In this episode:

  • Career insurance
  • In the trenches together
  • Who are you actually selling to?
  • Common sense, uncommon in sales

A huge thanks to our sponsor, Material Security

Legacy email security only watches the door. Material protects your entire cloud workspace—email, files, and accounts—as one ecosystem. It's more coverage for less than the cost of a legacy SEG. One price, no surprises: just security that covers the whole surface area. Learn more at material.security.

View Details

All links and images can be found on CISO Series

We think of cybersecurity as a discipline. But when do ideas like best practices and NIST frameworks change into a system of belief?

Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Davi Ottenheimer, principal, Flying Penguin. Joining is Joshua Copeland, director of security, Crescendo.

In this episode:

  • Tools, not religion
  • The case for structured discipline
  • The management problem underneath
  • Fix the damn holes

A huge thanks to our sponsor, ThreatLocker

ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.

View Details

All links and images can be found on CISO Series

We know human-paced security controls can't be applied to autonomous AI agents. So what needs to change with CNAPP and cloud security?

Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Dan Benjamin, vp product - data, identity, and AI security, Palo Alto Networks.

In this episode:

  • The detection ceiling
  • A category gap, not a feature gap
  • Resilience by design
  • An insider threat with no face

A huge thanks to our sponsor, Palo Alto Networks

Cortex Cloud unifies code, cloud, and SOC on a single data, risk, and control plane — giving teams the context, workflows, and agentic intelligence to turn risk into resolution. Native AI agents investigate and act within enterprise guardrails, delivering real-time protection from workload to network edge. Cloud security that outpaces machine-speed threats. Visit Palo Alto Networks and search cortex cloud.

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is our guest, Paul Guerra.

In this episode:

  • Read the contract
  • How vendors win before the evaluation ends
  • The fallout
  • The real cost

A huge thanks to our sponsor, Native Security

Native makes secure-by-design inherent to how the cloud operates. It's the control plane for built-in cloud security, unifying and governing native controls, so security intent is defined once and applied consistently across providers. Learn more at native.security.

View Details

All links and images can be found on CISO Series

All security startups will tell you they talk to potential customers. The problem is that you limit your development when you only talk to CISOs who might buy. It's not the same guidance you'll get from a CISO who advises.

Check out this post by Val Tsanev of the Cyber Risk Alliance for the discussion that is the basis of our conversation.

This week's episode is co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Steve Jensen, CISO, University of Maine System.

In this episode:

  • Building for whom?
  • The only feedback loop that matters
  • Valid, but for whom?
  • Rethink the advisor roster

A huge thanks to our sponsor, Material Security

Legacy email security only watches the door. Material protects your entire cloud workspace—email, files, and accounts—as one ecosystem. It's more coverage for less than the cost of a legacy SEG. One price, no surprises: just security that covers the whole surface area. Learn more at material.security.

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Rob Allen.

In this episode:

  • The vulnerable stack
  • Changing the structural economics
  • Change the terrain
  • The cost-benefit equation

A huge thanks to our sponsor, ThreatLocker

ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.

View Details

All links and images can be found on CISO Series

Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Heath Renfrow, co-founder, Fenix24.

In this episode:

  • Knowing which systems to save first
  • Recovery is a business conversation, not an IT ticket
  • Not all systems are created equal
  • Recovery knowledge as a governed asset

A huge thanks to our sponsor, Fenix24

Fenix24 is the world's leading breach recovery firm, providing rapid ransomware restoration, full asset visibility, and threat informed hardening. Alongside expert recovery services, Fenix24 delivers ongoing managed protection that secures backups, infrastructure, and critical controls, helping organizations stay resilient, recoverable, and prepared for modern cyber threats. Learn more at fenix24.com.

View Details

What Makes a Successful Security Vendor Demo?

All links and images can be found on CISO Series.

Check out this post from Adam Palmer for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Geoff Belknap. Joining is Ken Beasley, BISO, Kaiser Permanente.

In this episode:

  • Show me the problem, not the product
  • Walking in blind
  • Discovery is the demo
  • Define the use case, set the clock

A huge thanks to our sponsor, Fenix24

Fenix24 is the world's leading breach recovery firm, providing rapid ransomware restoration, full asset visibility, and threat informed hardening. Alongside expert recovery services, Fenix24 delivers ongoing managed protection that secures backups, infrastructure, and critical controls, helping organizations stay resilient, recoverable, and prepared for modern cyber threats. Learn more at fenix24.com.

View Details

Should You Use Native or 3rd Party Cloud Management Tools?

All links and images can be found on CISO Series.

Check out this post from Steve Zalewski for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is their sponsored guest, Gal Ordo, co-founder and CPO, Native.

In this episode:

  • More tools, more problems
  • A gap in design
  • Catching what slips through
  • Competence over complexity

A huge thanks to our sponsor, Native Security

Native makes secure-by-design inherent to how the cloud operates. It's the control plane for built-in cloud security, unifying and governing native controls, so security intent is defined once and applied consistently across providers. Learn more at native.security.

View Details

How Should We Measure the Performance of a CISO?

All links and images can be found on CISO Series.

Check out this post from the cybersecurity subreddit for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining them is Jason Richards, vp, information security, CHG Healthcare.

In this episode:

  • Likability as a career strategy
  • The storytelling gap
  • How the math actually gets done
  • The unofficial scorecard

A huge thanks to our sponsor, ThreatLocker

ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Ross Young, co-host, CISO Tradecraft. Joining them is Dan Walsh, CISO, Datavant. Be sure to check out Ross's book Cybersecurity's Dirty Secret: Why Most Budgets Go to Waste.

In this episode:

  • Patterns hiding in plain sight
  • Activity vs. advancement
  • The human cost
  • Frameworks about frameworks

A huge thanks to our sponsor, Fenix24

Fenix24 is the world's leading breach recovery firm, providing rapid ransomware restoration, full asset visibility, and threat informed hardening. Alongside expert recovery services, Fenix24 delivers ongoing managed protection that secures backups, infrastructure, and critical controls, helping organizations stay resilient, recoverable, and prepared for modern cyber threats. Learn more at fenix24.com.

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week's episode, co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining them is Adam Palmer, CISO, First Hawaiian Bank. Be sure to check out David's book, Three Feet from Seven Figures: One-on-One Engagement Techniques to Qualify More Leads at Trade Shows.

In this episode:

  • Lead with insight, not persuasion
  • Recognize the opportunity when it arrives
  • Strategy over features
  • Keep it efficient

A huge thanks to our sponsor, Endor Labs

Discover how AI coding agents are reshaping software supply chain risk in the State of Dependency Management. Original research from Endor Labs shows 49% of dependency versions have known vulnerabilities (and that 34% don't actually exist). Get the report to see how "shadow AI" is reshaping attack surfaces. Learn more at endorlabs.com.

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week's episode, co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining is their sponsored guest, Matt Brown, solutions architect, Endor Labs.

In this episode:

  • The development disconnect
  • Functionality first, security second
  • The incentive problem
  • Speed as the common ground

A huge thanks to our sponsor, Endor Labs

Discover how AI coding agents are reshaping software supply chain risk in the State of Dependency Management. Original research from Endor Labs shows 49% of dependency versions have known vulnerabilities (and that 34% don't actually exist). Get the report to see how "shadow AI" is reshaping attack surfaces. Learn more at www.endorlabs.com.

View Details

All links and images can be found on CISO Series.

Check out this post by Caleb Sima for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Evan McHenry, CISO, Robinhood.

In this episode:

  • The information paradox
  • Setting realistic expectations
  • Prioritization over noise
  • The cart before the horse

Huge thanks to our sponsor, Endor Labs

Discover how AI coding agents are reshaping software supply chain risk in the State of Dependency Management. Original research from Endor Labs shows 49% of dependency versions have known vulnerabilities (and that 34% don't actually exist). Get the report to see how "shadow AI" is reshaping attack surfaces.

View Details

All links and images can be found on CISO Series.

Check out this post, CISO, Upwind Security, for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Geoff Belknap, CISO, LinkedIn. Joining us is Octavia Howell, vp and CISO, Equifax Canada.

In this episode:

  • Beyond the quota
  • The hard truth beats the polished bluff
  • Paying for someone else's mistakes
  • Reducing friction, increasing trust

Huge thanks to our sponsor, ThreatLocker

ThreatLocker takes a deny-by-default approach to endpoint security — controlling what applications can run, what can access data, and what can elevate privileges. Used by organizations that want to reduce attack surface without relying on detection alone. Learn more at threatlocker.com/ciso.

View Details

All links and images can be found on CISO Series.

This week's episode is co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Mark Eggleston, CISO, CSC.

In this episode:

  • Breaking trust to test it
  • Technical controls over testing
  • The measurement imperative
  • Fire drills, not gotchas

Huge thanks to our sponsor, Scanner

All your security logs end up in cloud storage like AWS S3. Scanner makes them searchable in seconds and runs real-time detections directly on that data. No pipelines, no re-ingestion. 100x faster than traditional data lakes, 10x cheaper than SIEMs. Loved by analysts. Built for AI agents. Learn more at scanner.dev.

View Details

All links and images can be found on CISO Series.

This week's episode is co-hosted by me, David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Cliff Crosland, co-founder and CEO, Scanner.dev.

In this episode:

  • Earning autonomy gradually
  • The blast radius question
  • The reality check
  • Today's value, tomorrow's evolution

Huge thanks to our sponsor, Scanner

All your security logs end up in cloud storage like AWS S3. Scanner makes them searchable in seconds and runs real-time detections directly on that data. No pipelines, no re-ingestion. 100x faster than traditional data lakes, 10x cheaper than SIEMs. Loved by analysts. Built for AI agents. Learn more at scanner.dev.

View Details

All links and images can be found on CISO Series.

Check out this post by Dr. Chase Cunningham, CSO at Demo-Force, for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Geoff Belknap. Joining us is Brett Conlon, CISO, American Century Investments.

In this episode:

  • The experience paradox
  • Who benefits from the narrative
  • Kitchen sink job postings
  • The aggregation problem

Huge thanks to our sponsor, Scanner

All your security logs end up in cloud storage like AWS S3. Scanner makes them searchable in seconds and runs real-time detections directly on that data. No pipelines, no re-ingestion. 100x faster than traditional data lakes, 10x cheaper than SIEMs. Loved by analysts. Built for AI agents. Learn more at scanner.dev

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week's episode, co-hosted by David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining them is their sponsored guest, Rob Allen, chief product officer, ThreatLocker.

In this episode:

  • Getting permissions right
  • The fundamentals that still fail
  • Know what you have
  • Simple controls, outsized impact

Huge thanks to our sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

View Details

All links and images can be found on CISO Series.

Check out this post by Patrick Garrity of VulnCheck for the discussion that is the basis of our conversation on this week's episode, co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining them is Tom Doughty, CISO, Generate:Biomedicines.

In this episode:

  • The 3Ms of product clarity
  • Buzzwords work because buyers aren't experts
  • Investor pressures distort messaging
  • Threading the needle

Huge thanks to our sponsor, Alteryx

Alteryx is a leading AI and data analytics company that powers actionable insights that help organizations drive smarter, faster decisions. Alteryx One helps security, risk, and operations leaders cut hours of manual work to minutes, generate trusted insights at scale, and turn raw data into action faster than ever. Learn more at www.alteryx.com.

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week's episode, co-hosted by David Spark, the producer of CISO Series, and Geoff Belknap. Joining them is sponsored guest Matt Goodrich, director of information security, Alteryx.

In this episode:

  • The integrity challenge
  • Zero trust for AI outputs
  • Guardrails over garbage
  • It looks good...

Huge thanks to our sponsor, Alteryx

Alteryx is a leading AI and data analytics company that powers actionable insights that help organizations drive smarter, faster decisions. Alteryx One helps security, risk, and operations leaders cut hours of manual work to minutes, generate trusted insights at scale, and turn raw data into action faster than ever. Learn more at www.alteryx.com.

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week's episode, co-hosted by me, David Spark, the producer of CISO Series, and Jerich Beason, CISO, WM. Their guest is Pam Lindemoen, CSO and vp of strategy, RH-ISAC.

In this episode:

  • From loudest to most trusted
  • Letting go of the win
  • Listening over proving
  • Beyond right and wrong

Huge thanks to our sponsor, Alteryx

Alteryx is a leading AI and data analytics company that powers actionable insights that help organizations drive smarter, faster decisions. Alteryx One helps security, risk, and operations leaders cut hours of manual work to minutes, generate trusted insights at scale, and turn raw data into action faster than ever. Learn more at www.alteryx.com.

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Ejona Preci, group CISO, LINDAL Group.

In this episode:

  • Consequence, not controls
  • The credibility gap
  • Defining the undefined
  • Expanding the mandate

A huge thanks to our sponsor, ThreatLocker

ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.

View Details

All links and images can be found on CISO Series.

Check out this post by Binoy Koonammavu of Secusy AI for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining them is best-selling cybersecurity author Peter Gregory. His upcoming study guide on AI governance can be pre-ordered here.

In this episode:

  • Speaking the language of leadership
  • Beyond translation: the trust factor
  • Making risk tangible
  • When translation isn't enough

Huge thanks to our sponsor, ThreatLocker

ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.

View Details

All links and images can be found on CISO Series.

Check out this post by Nick Nolen of Redpoint Cyber for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Geoff Belknap. Joining us is Erika Dean, former CSO, Robinhood.

In this episode:

  • Delegation requires accountability
  • The reality of daily decision-making
  • The gap between theory and practice
  • Beyond the advisory role

Huge thanks to our sponsor, ThreatLocker

ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO

View Details

All links and images can be found on CISO Series.

Check out this post by Christofer Hoff of Truist for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Caleb Sima, builder, WhiteRabbit. Joining them is Crystal Chatam, vp of cybersecurity, Speedcast.

In this episode:

  • Understanding the fundamentals
  • The grift of superficial expertise
  • Hands-on experience matters
  • A vulnerability at the leadership level

Huge thanks to our sponsor, Stellar Cyber

By shining a bright light on the darkest corners of security operations, Stellar Cyber empowers organizations to see incoming attacks, know how to fight them, and act decisively – protecting what matters most. Stellar Cyber's award-winning open security operations platform includes AI-driven SIEM, NDR, ITDR, Open XDR, and Multi-Layer AI™ under one unified platform with a single license. With ⅓ of the global top 250 MSSPs and over 14,000 customers worldwide, Stellar Cyber is one of the most trusted leaders in security operations. Learn more at https://stellarcyber.ai/.

View Details

All links and images can be found on CISO Series.

Check out this post by Ross Haleliuk of Venture in Security for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Davi Ottenheimer, vp, trust and digital ethics, Inrupt.

In this episode:

  • Network security isn't dying—it's evolving
  • The observability layer that can't be replaced
  • What's old is new again
  • The innovation gap

Huge thanks to our sponsor, HackerOne

Discover how AI innovators like Adobe, Anthropic, and Snap are using AI to find and fix vulnerabilities across the software development lifecycle. HackerOne, the global leader in offensive security solutions, reveals all in the CISOs' guide to securing the future of AI. Download it now to see how AI can strengthen your security posture. Learn more at https://www.hackerone.com/

View Details

All links and images can be found on CISO Series.

Check out this post by Kevin Paige, CISO at ConductorOne, for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Geoff Belknap. Joining us is our sponsored guest, Rob Allen, chief product officer, ThreatLocker.

In this episode:

  • When configuration drift becomes operational reality
  • The garden that never stops growing
  • From detection to cultural shift
  • The maturity gap

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® Defense Against Configurations continuously scans endpoints to uncover misconfigurations, weak firewall rules, and risky settings that weaken defenses. With compliance mapping, daily updates, and actionable remediation in one dashboard, it streamlines hardening, reduces attack surfaces, and strengthens security. Learn more at https://www.threatlocker.com/

View Details

All links and images can be found on CISO Series.

Check out this post by Kevin Paige, CISO at ConductorOne, for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining them is Julie Tsai, CISO-in-Residence, Ballistic Ventures.

In this episode:

  • Is least privilege dead?
  • Modern tactics, timeless principle
  • Implementation over ideology
  • Pragmatism over purity

Huge thanks to our sponsor, Cyera

AI is moving fast - can your security keep up? Join the leaders shaping the future of data and AI security at DataSecAI Conference 2025, hosted by Cyera, Nov 12–13 in Dallas. Register now at https://datasecai2025.com/did.

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Mike Johnson, CISO, Rivian. Joining them is their sponsored guest Bobby Ford, chief strategy and experience officer, Doppel.

In this episode:

  • Beyond the click
  • High-risk users demand different metrics
  • Building engagement over punishment
  • Creating a security culture through community

Huge thanks to our sponsor, Doppel

Doppel is protecting the world's digital integrity. Impersonators adapt fast — but so does Doppel. By pairing AI with expert analysis, we don't just detect deception; we dismantle it. Our platform learns from every attack, expands its reach across digital channels, and disrupts threats before they cause harm. The result? Impersonators lose. Businesses become too costly to attack. And trust stays intact. Learn more at https://www.doppel.com/

View Details

All links and images can be found on CISO Series.

Check out this post by Mike Gallardo for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Geoff Belknap. Joining them is Alex Guilday, BISO, Royal Caribbean Group.

In this episode:

  • Timing the approach
  • When persistence becomes harassment
  • Playing the long game
  • The necessity argument

Huge thanks to our sponsor, Cyera

AI is moving fast - can your security keep up? Join the leaders shaping the future of data and AI security at DataSecAI Conference 2025, hosted by Cyera, Nov 12–13 in Dallas. Register now at https://datasecai2025.com/did.

View Details

All links and images can be found on CISO Series.

Check out this post by Evgeniy Kharam for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining them is Ryan Dunn, Leader of Product and Supply Chain Technology, Specialized Bicycle Components.

And check out "Architecting Success: The Art of Soft Skills in Technical Sales: Connect to Sell More" by Evgeniy Kharam we referenced in this episode.

In this episode:

  • Beyond the technical playbook
  • Influencing without authority
  • Partnering, not just selling
  • The deliberate work of connection

Thanks to our sponsor, HackerOne

Built on 580,000+ validated vulnerabilities, $81M in payouts this year, and insights from 1,950 enterprise programs, the 2025 Hacker-Powered Security Report shows how leading organizations reduce risk and prove outcomes. Get practical guidance on attacker focus, response patterns, and board-ready metrics. Watch the Q&A, then download the report to operationalize what works for you. https://www.hackerone.com/report/future-of-ai?utm_medium=Paid-Newsletter&utm_source=cisoseries&utm_campaign=Parent-FY25-AIAwarenessCampaign-GL

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by David Spark, the producer of CISO Series, and Bil Harmer, security advisor, Craft Ventures. Joining them is James Bruce, business security services director, WPP.

In this episode:

  • Turning visibility into actionable intelligence
  • Pure visibility still provides an essential security foundation
  • Finding strategic value
  • The risk of gaps in identity management

Huge thanks to our sponsor, ThreatLocker

Human error remains one of the top cybersecurity threats. Just one wrong click can open the door to ransomware or data loss. With ThreatLocker, unauthorized apps, scripts, and devices are blocked before they can ever run. See how ThreatLocker can help you gain more control over your environment. Threatlocker.com/CISO

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by David Spark, the producer of CISO Series, and Dan Walsh, CISO, Datavant. Joining them is their sponsored guest, Ash Hunt, vp, strategy, EMEA, Cyera.

In this episode:

  • The access creep challenge
  • Bridging intent and execution
  • Looking for integrity
  • Racing against exponential complexity

Huge thanks to our sponsor, Cyera

AI is moving fast - can your security keep up? Join the leaders shaping the future of data and AI security at DataSecAI Conference 2025, hosted by Cyera, Nov 12–13 in Dallas. Register now at https://www.cyera.com/?utm_source=cisoseries

View Details

All links and images can be found on CISO Series.

Check out this post by David Mundy of Tuskira for the discussion that is the basis of our conversation on this week’s episode co-hosted by David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining them is Jason Taule, CISO, Luminis Health.

In this episode:

  • ROI challenges
  • Venture capital saturation
  • Risk aversion and organizational politics
  • A GTM transformation

Huge thanks to our sponsor, Doppel

Doppel is the first social engineering defense platform built to dismantle deception at the source. It uses AI and infrastructure correlation to detect, link, and disrupt impersonation campaigns before they spread - protecting brands, executives, and employees while turning every threat into action that strengthens defenses across a shared intelligence network. Learn more at https://www.doppel.com/platform

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Geoff Belknap. Joining us is our sponsored guest, Kara Sprague, CEO, HackerOne.

In this episode:

  • Shadow AI as a control problem
  • Rethinking identity for autonomous agents
  • When process meets momentum
  • Beyond blocking: channeling AI usage

Huge thanks to our sponsor, HackerOne

Discover how AI innovators like Adobe, Anthropic, and Snap are using AI to find and fix vulnerabilities across the software development lifecycle. HackerOne, the global leader in offensive security solutions, reveals all in the CISOs’ guide to securing the future of AI. Download it now to see how AI can strengthen your security posture. Learn more at https://www.hackerone.com/

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is CISO Series reporter and CISO herself, Hadas Cassorla.

In this episode:

  • Security poverty line excludes SMBs
  • Skills gap and channel dynamics slow SMB security adoption
  • The startup disadvantage cycle
  • Technology adoption flows from enterprise complexity to market simplification

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by David Spark, the producer of CISO Series, and Geoff Belknap. Joining us is our sponsored guest Mokhtar Bacha, founder and CEO, Formal.

In this episode:

  • Access management faces transformation
  • AI agents demand new authentication paradigms
  • AI complexity demands simplified governance approaches
  • Data-centric identity management replaces role-based approaches

Huge thanks to our sponsor, Formal

Formal secures humans, AI agent’s access to MCP servers, infrastructure, and data stores by monitoring and controlling data flows in real time. Using a protocol-aware reverse proxy, Formal enforces least-privilege access to sensitive data and APIs, ensuring AI behavior stays predictable and secure. Visit joinformal.com to learn more or schedule a demo.

View Details

All links and images can be found on CISO Series.

Check out this post by Geoff Belknap, co-host of Defense in Depth, for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and John Overbaugh, CISO, Alpine Investors. Joining us is our sponsored guest, Pukar Hamal, founder and CEO at SecurityPal.

In this episode:

  • When business moves faster than security
  • Turning obstacles into opportunities
  • The art of saying "not like that"
  • Know your regulatory landscape

Huge thanks to our sponsor, SecurityPal AI

SecurityPal is the leader in Customer Assurance, helping companies accelerate security assurance without compromising accuracy. Their AI + human expertise approach, dynamic Trust Center, and modern TPRM solution eliminate manual work and streamline vendor security at scale. To learn more, visit securitypal.ai.

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Justin Berman, formerly vp of platform engineering and CISO at Thirty Madison Health.

In this episode:

  • Maps without transportation
  • The untouchable employee problem
  • Attestation theater
  • The lightbulb moment

Huge thanks to our sponsor, SecurityPal

SecurityPal is the leader in Customer Assurance, helping companies accelerate security assurance without compromising accuracy. Their AI + human expertise approach, dynamic Trust Center, and modern TPRM solution eliminate manual work and streamline vendor security at scale. To learn more, visit securitypal.ai.

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Rob Allen, chief product officer, ThreatLocker.

In this episode:

  • Legacy infrastructure creates the biggest hurdles
  • More marketing than methodology
  • Implementation complexity makes zero trust a Sisyphean task
  • Don't ignore human factors

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit Threatlocker.com/CISO

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Steve Zalewski. Joining them is Terry O'Daniel, former CISO at Amplitude.

In this episode:

  • Beyond prioritization: aligning risk with reality
  • From signals to strategy
  • The Case for Maturity Models
  • Security Starts With Culture

Huge thanks to our sponsor, SecurityPal

SecurityPal is the leader in Customer Assurance, helping companies accelerate security assurance without compromising accuracy. Their AI + human expertise approach, dynamic Trust Center, and modern TPRM solution eliminate manual work and streamline vendor security at scale. To learn more, visit securitypal.ai.

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining them is their sponsored guest, Matt Eberhart, CEO, Query.

In this episode:

  • Quality over quantity in AI decision-making
  • Process before technology
  • The connectivity challenge
  • The context complexity paradox

Huge thanks to our sponsor, Query

Query is a Federated Search and Analytics platform that builds a security data mesh, giving security teams real-time context from all connected sources. Analysts move faster and make better decisions with AI agents and copilots that handle the grunt work and guide each step. Learn more at query.ai

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is Jason Thomas, senior director, technology security, governance, and risk, Cystic Fibrosis Foundation.

In this episode:

  • The trust deficit
  • Defending the non-technical roles
  • The business accountability gap
  • The communication imperative

Huge thanks to our sponsor, Query.ai

Query is a Federated Search and Analytics platform that builds a security data mesh, giving security teams real-time context from all connected sources. Analysts move faster and make better decisions with AI agents and copilots that handle the grunt work and guide each step. Learn more at query.ai

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode, co-hosted by me, David Spark, the producer of CISO Series, and Dan Walsh, CISO, Datavant. Joining them is Sneha Parmar, former information security officer, Lufthansa Group Digital.

In this episode:

  • Shifting left, broadening out
  • The insurance wake-up call
  • Building trust into the system
  • Security’s identity crisis

A huge thanks to our sponsor, Doppel

Doppel is the first social engineering defense platform built to dismantle deception at the source. It uses AI and infrastructure correlation to detect, link, and disrupt impersonation campaigns before they spread - protecting brands, executives, and employees while turning every threat into action that strengthens defenses across a shared intelligence network. Learn more at https://www.doppel.com/platform

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is David Cross, CISO, Atlassian.

In this episode:

  • The experience prerequisite
  • The bootcamp reality check
  • The compensation conundrum
  • The domain expertise imperative

A huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

All posts and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Geoff Belknap. Joining us is Steve Knight, former CISO, Hyundai Capital America.

In this episode:

  • Streamlining vendor evaluations
  • Moving beyond compliance theater
  • The scorecard skeptics
  • Finding the right balance

Thanks to our sponsor, Formal

Formal secures humans, AI agent’s access to MCP servers, infrastructure, and data stores by monitoring and controlling data flows in real time. Using a protocol-aware reverse proxy, Formal enforces least-privilege access to sensitive data and APIs, ensuring AI behavior stays predictable and secure. Visit joinformal.com to learn more or schedule a demo.

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by David Spark, the producer of CISO Series, and Mike Johnson, CISO, Rivian. Joining is Hanan Szwarcbord, vp, CSO and head of infrastructure, Micron Technology.

In this episode

  • Embracing growth
  • An urgent need for creativity
  • Get the business context
  • Embrace your inner theater kid

Huge thanks to our sponsor, Query.ai

Query is a Federated Search and Analytics platform that builds a security data mesh, giving security teams real-time context from all connected sources. Analysts move faster and make better decisions with AI agents and copilots that handle the grunt work and guide each step. Learn more at query.ai

View Details

All links and images can be found on CISO Series.

Check out this post by Justin Pagano at Klaviyo for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Geoff Belknap. Joining us is Jesse Webb, CISO and svp information systems, Avalon Healthcare Solutions.

In this episode:

  • Align the incentives
  • The feature and enforcement disconnect
  • Putting the right people in the right place
  • A need for transparency

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest Jason Steer, CISO, Recorded Future.

In this episode

  • We don't need more indicators
  • Creating more work
  • Generating actionable intelligence
  • Design for what you can do

Huge thanks to our sponsor, Recorded Future

Every day, security teams face an impossible challenge: sorting through millions of threats, each potentially critical. But somewhere in that noise are the signals you can't afford to miss. Recorded Future's gives you the power to outpace AI-driven threats through intelligence tuned specifically to your needs, enabling you to act with precision. Their advanced AI detects patterns human eyes might miss, while their experts provide context that machines alone cannot. Visit recordedfuture.com to learn more about securing what matters to your business.

View Details

All images and links can be found on CISO Series.

Check out this post by Gautam ‘Gotham’ Sharma of AccessCyber for the discussion that is the basis of our conversation on this week’s episode, co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is Krista Arndt, associate CISO, St. Luke’s University Health Network.

In this episode:

  • Verify then trust
  • Dishonesty on all sides
  • A lack of flexibility
  • What about integrity?

Huge thanks to our sponsor, Formal

Formal secures humans, AI agent’s access to MCP servers, infrastructure, and data stores by monitoring and controlling data flows in real time. Using a protocol-aware reverse proxy, Formal enforces least-privilege access to sensitive data and APIs, ensuring AI behavior stays predictable and secure. Visit joinformal.com to learn more or schedule a demo.

View Details

All links and images can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Joining us is Dennis Pickett, vp, CISO, Westat.

In this episode:

  • Stop siloing cybersecurity
  • Leading the charge
  • A culture of ownership
  • Preparing for resilience

A huge thanks to our sponsor, Recorded Future

Every day, security teams face an impossible challenge: sorting through millions of threats, each potentially critical. But somewhere in that noise are the signals you can’t afford to miss. Recorded Future’s gives you the power to outpace AI-driven threats through intelligence tuned specifically to your needs, enabling you to act with precision. Their advanced AI detects patterns human eyes might miss, while their experts provide context that machines alone cannot. Visit recordedfuture.com to learn more about securing what matters to your business.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Yaron Levi, CISO, Dolby. Joining us is Joey Rachid, CISO, Xerox.

In this episode:

  • It's a balancing act
  • Choose to leave the kids' table
  • Your team is essential
  • Don't change CISOs midstream

Huge thanks to our sponsor, Blackslash

Backslash offers a new approach to application security by creating a digital twin of your application, modeled into an AI-enabled App Graph. It categorizes security findings by business process, filters “triggerable” vulnerabilities, and simulates the security impact of updates. Backslash dramatically improves AppSec efficiency, eliminating legacy SAST and SCA frustration. Learn more at https://www.backslash.security/

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Howard Holton, COO, Gigaom. Joining us is our sponsored guest, Rob Allen, chief product officer at ThreatLocker.

In this episode:

  • Reinforcing zero trust
  • Focus on effectiveness
  • Understanding zero trust limitations
  • What's next

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is Jay Jay Davey, vp of cyber security operations, Planet.

In this episode:

  • Aligning incentives
  • The realities of the job
  • Delivering ROI
  • Holistic cybersecurity

Thanks to our sponsor, Backslash Security

Backslash offers a new approach to application security by creating a digital twin of your application, modeled into an AI-enabled App Graph. It categorizes security findings by business process, filters “triggerable” vulnerabilities, and simulates the security impact of updates. Backslash dramatically improves AppSec efficiency, eliminating legacy SAST and SCA frustration. Learn more at www.backslash.security.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Eric Gold, chief evangelist, BackSlash.

In this episode:

  • Start with the culture
  • Moving AppSec to a higher level
  • A strategy for security
  • Maturing the basics

Thanks to our sponsor, Backslash Security

Backslash offers a new approach to application security by creating a digital twin of your application, modeled into an AI-enabled App Graph. It categorizes security findings by business process, filters “triggerable” vulnerabilities, and simulates the security impact of updates. Backslash dramatically improves AppSec efficiency, eliminating legacy SAST and SCA frustration.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post from Jerich Beason, CISO at WM, for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Dan Walsh, CISO, Datavant. Joining us is Rinki Sethi, vp and CISO, BILL.

In this episode:

  • You need a solid foundation
  • A lot depends on the role
  • Underappreciated skills
  • Structures and frameworks

Huge thanks to our sponsor, Recorded Future

Every day, security teams face an impossible challenge: sorting through millions of threats, each potentially critical. But somewhere in that noise are the signals you can't afford to miss. Recorded Future's gives you the power to outpace AI-driven threats through intelligence tuned specifically to your needs, enabling you to act with precision. Their advanced AI detects patterns human eyes might miss, while their experts provide context that machines alone cannot. Visit recordedfuture.com to learn more about securing what matters to your business.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post from Caleb Sima of WhiteRabbit for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Geoff Belknap. Joining us is Alex Hutton, CISO, Atlantic Union Bank.

In this episode:

  • The race to differentiate
  • Don’t blame Gartner
  • Simplifying is complicated
  • Seeking connection

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Jason Elrod, CISO, MultiCare Health System. Joining us is our sponsored guest, Nick Muy, CISO, Scrut Automation.

In this episode:

  • Supercharging teams
  • Shifting to proactive
  • A unique opportunity
  • A human in the legal loop

HUGE thanks to our sponsor, Scrut Automation

Scrut Automation empowers compliance and risk teams of all sizes to build enterprise-grade security programs effortlessly. With powerful automation, AI-driven efficiencies, and seamless integrations, Scrut eliminates compliance debt and enables proactive risk management—helping your business stay secure as it scales. Visit www.scrut.io to learn more or schedule a demo.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post by Tallis Jordan of the U.S. Army Cyber Command for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is Montez Fitzpatrick, CISO, Navvis.

In this episode:

  • Start with foundations
  • Learning to learn
  • Don’t get hustled
  • Building a pipeline

HUGE thanks to our sponsor, Scrut Automation

Scrut Automation empowers compliance and risk teams of all sizes to build enterprise-grade security programs effortlessly. With powerful automation, AI-driven efficiencies, and seamless integrations, Scrut eliminates compliance debt and enables proactive risk management—helping your business stay secure as it scales. Visit www.scrut.io to learn more or schedule a demo.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post from Yaron Levi for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Mike Johnson, CISO, Rivian. Joining us is Yaron Levi, CISO, Dolby.

In this episode:

  • A knowledge deficit
  • Talk is cheap
  • What’s the difference?
  • Answer the preliminaries

HUGE thanks to our sponsor, Scrut Automation

Scrut Automation empowers compliance and risk teams of all sizes to build enterprise-grade security programs effortlessly. With powerful automation, AI-driven efficiencies, and seamless integrations, Scrut eliminates compliance debt and enables proactive risk management—helping your business stay secure as it scales. Visit www.scrut.io to learn more or schedule a demo.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post by Rachel Bicknell of Dell Technologies quoting Mic Merritt of Merritt Collective for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Jimmy Sanders, president, ISSA International. Joining them is Ngozi Eze, CISO, Levi Strauss.

In this episode:

  • Stop the unicorn hunt
  • Job post inflation
  • Structural misalignment
  • We’ve got to do better

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Howard Holton, CTO, GigaOm. Joining us is Francis Odum, founder, Software Analyst Cybersecurity Research.

In this episode:

  • Rebalancing the SOC
  • The case for consolidation
  • It comes down to data
  • Concentric cycles

Thanks to our podcast sponsor, Palo Alto Networks

Cortex Cloud, the next generation of Prisma Cloud, merges best-in-class CDR with industry-leading CNAPP for real-time cloud security. Harness the power of AI and automation to prioritize risks with runtime context, enable remediation at scale, and stop attacks as they occur. Bring together your cloud and SOC on the unified Cortex platform to transform end-to-end operations. Experience the future of real-time cloud security at https://www.paloaltonetworks.com/cortex/cloud.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Lee Parrish, CISO, Newell Brands. Joining us is David Tyburski, vp of information security and CISO, Wynn Resorts.

In this episode:

  • CISOs need to stick around
  • Culture forward
  • CISOs need support
  • This isn’t always about budget

Thanks to our podcast sponsor, Palo Alto Networks!

Cortex Cloud, the next generation of Prisma Cloud, merges best-in-class CDR with industry-leading CNAPP for real-time cloud security. Harness the power of AI and automation to prioritize risks with runtime context, enable remediation at scale, and stop attacks as they occur. Bring together your cloud and SOC on the unified Cortex platform to transform end-to-end operations. Experience the future of real-time cloud security at https://www.paloaltonetworks.com/cortex/cloud.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Joining us is Elad Koren, vp, product management, Cortex Cloud, Palo Alto Networks.

In this episode:

  • Context drives the decision
  • A full-spectrum understanding
  • Think practical
  • The long play

Thanks to our podcast sponsor, Palo Alto Networks

Cortex Cloud, the next generation of Prisma Cloud, merges best-in-class CDR with industry-leading CNAPP for real-time cloud security. Harness the power of AI and automation to prioritize risks with runtime context, enable remediation at scale, and stop attacks as they occur. Bring together your cloud and SOC on the unified Cortex platform to transform end-to-end operations. Experience the future of real-time cloud security at https://www.paloaltonetworks.com/cortex/cloud.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and DJ Schleen, former distinguished security architect, Yahoo. Joining us is our sponsored guest Heath Renfrow, co-founder, Fenix24.

In this episode:

  • Get creative
  • Shift the focus of backups
  • Failing the test
  • Moving beyond false hope

Thanks to our podcast sponsor, Fenix24

You’ve invested in cybersecurity, but can your business recover when it counts? The Securitas Summa program from the Conversant Group combines resistance, managed protection, and rapid recovery to minimize downtime and restore operations faster than anyone else. Resilience isn’t optional. Click to see how it works.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Joining us is Andrew Wilder, CISO, Vetcor.

In this episode:

  • It comes down to growth
  • Maintenance mode is anything but simple
  • An asymmetric arrangement
  • Integrating with the business

Thanks to our podcast sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Joining us Sneha Parmar, information security officer, Lufthansa Group Digital Hangar.

In this episode:

  • Build the foundation
  • Building at scale
  • Excelling at boring
  • Knowing what you’ve got is half the battle

Thanks to our podcast sponsor, Fenix24

You’ve invested in cybersecurity, but can your business recover when it counts? The Securitas Summa program from the Conversant Group combines resistance, managed protection, and rapid recovery to minimize downtime and restore operations faster than anyone else. Resilience isn’t optional. Click to see how it works.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Mike Johnson, CISO, Rivian. Joining us is Gaurav Kapil, CISO, Bread Financial.

In this episode:

  • It helps to have a vision
  • The benefit of planning
  • It’s never too early to start
  • Don’t make rash decisions

Thanks to our podcast sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post by Marc Ashworth, CISO at First Bank for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Shawn Bowen, vp, deputy CISO - Gaming, Microsoft. Joining us is Ken Athanasiou, CISO, VF Corporation.

In this episode:

  • Frustration is a two-way street
  • Sales is data driven
  • Give customers the tools they need
  • Start a conversation

Thanks to our podcast sponsor, Noma Security

Secure your entire Data & AI Lifecycle—from development to production and classic data engineering to GenAI. Noma’s full-lifecycle platform delivers seamless protection against risks like misconfigured data pipelines, malicious models, and adversarial AI attacks, empowering AppSec teams with complete visibility, security, and compliance—without disrupting data and AI teams’ workflows.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Joining us is our sponsored guest, Rob Allen, chief product officer, ThreatLocker.

In this episode:

  • The promise and perils of LLMs
  • A boon for defenders
  • Raising the bar
  • Muddying the waters

Thanks to our podcast sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Ross Young, CISO-in-residence, Team8, and Jeroen Schipper, CISO, Gemeente Den Haag.

In this episode:

  • Creating authority
  • Don’t reinvent the wheel
  • Accountable for quality
  • Make the distinction clear

Thanks to our podcast sponsor, Fenix24

You’ve invested in cybersecurity, but can your business recover when it counts? The Securitas Summa program from the Conversant Group combines resistance, managed protection, and rapid recovery to minimize downtime and restore operations faster than anyone else. Resilience isn’t optional. Click to see how it works.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Itai Tevet, CEO, Intezer.

In this episode:

  • Build for what you can handle
  • Rethinking alerts
  • Building trust into your system
  • Seeing the bigger picture

Thanks to our podcast sponsor, Intezer

Intezer’s AI-driven solution automates alert triage and investigations, cutting through the noise to highlight serious threats. By integrating with your security tools, it escalates only 4% of alerts for fast remediation, helping SOC teams focus on what matters. Learn more at intezer.com today!

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Mike Johnson, CISO, Rivian. Joining us is Yaron Levi, CISO, Dolby.

In this episode:

  • You can’t manage what you don’t know you have
  • Vulnerability management doesn’t have an endpoint
  • This is about tradeoffs
  • A unique approach

Thanks to our podcast sponsor, Intezer

Intezer’s AI-driven solution automates alert triage and investigations, cutting through the noise to highlight serious threats. By integrating with your security tools, it escalates only 4% of alerts for fast remediation, helping SOC teams focus on what matters. Learn more at intezer.com today!

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Dan Walsh, CISO, Paxos. Joining us is Sharon Milz, CISO, Time.

In this episode:

  • A vicious cycle
  • Not all training is created equal
  • Don’t forget the human factor
  • We can still define success

Thanks to our podcast sponsor, Intezer

Intezer’s AI-driven solution automates alert triage and investigations, cutting through the noise to highlight serious threats. By integrating with your security tools, it escalates only 4% of alerts for fast remediation, helping SOC teams focus on what matters. Learn more at intezer.com today!

View Details

All links and images for this episode can be found on CISO Series.

Check out these posts for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Ross Haleliuk, author, Venture in Security. Be sure to check out Ross's podcast, Inside the Network, and his book Cyber for Builders: The Essential Guide to Building a Cybersecurity Startup.

In this episode:

  • A market response to industry failure
  • Is this a business or a feature?
  • The economics of startups
  • Practicality over novelty

Thanks to our podcast sponsor, Nudge Security

Manage SaaS security and governance at scale with Nudge Security. Discover all SaaS accounts ever created by anyone in your org on Day One, including genAI tools. Surface identity security risks and resolve them with automated playbooks. Start your free 14-day trial today.

View Details

All links and images for this episode can be found on CISO Series.

Check out these posts for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is Allan Cockriel, group CISO, Shell.

In this episode:

  • Striking a balance
  • Will we see a talent exodus?
  • Playing by the same rules
  • This is an organizational responsibility

Thanks to our podcast sponsor, SpyCloud

Cybercrime doesn’t take breaks. Protect your organization from ransomware, account takeover, and online fraud with SpyCloud. SpyCloud recaptures stolen identity data from breaches, infostealer malware, and phishing attacks that put your business at risk. Teams use SpyCloud’s advanced analytics and powerful automation to stay ahead of attackers. Visit spycloud.com for your free risk report and start disrupting cybercrime today.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest Karthik Krishnan, founder and CEO, Concentric AI.

In this episode:

  • Meet the new risk, same as the old risk
  • Understanding where your risks are coming from
  • Identifying best practices
  • Know what you’re getting into

Thanks to our podcast sponsor, Concentric AI

Concentric AI’s DSPM solution automates data security, protecting sensitive data in real-time. Our AI-driven solution identifies, classifies, and secures on-premises and cloud data to reduce risk across your enterprise. Seamlessly integrated with tools like Microsoft Copilot, Concentric AI empowers your team to innovate securely and maintain compliance all while eliminating manual data protection tasks.

Ready to put RegEx and trainable classifiers in the rear view mirror? Contact Concentric AI today!

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Damon Fleury, chief product officer, SpyCloud.

In this episode:

  • A holistic view
  • Adding sophistication to identity
  • Your employees can help
  • Cracking the code

Thanks to our podcast sponsor, SpyCloud

Cybercrime doesn’t take breaks. Protect your organization from ransomware, account takeover, and online fraud with SpyCloud. SpyCloud recaptures stolen identity data from breaches, infostealer malware, and phishing attacks that put your business at risk. Teams use SpyCloud’s advanced analytics and powerful automation to stay ahead of attackers. Visit spycloud.com for your free risk report and start disrupting cybercrime today.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Joining us is Joe Lewis, CISO, CDC.

In this episode:

  • Don’t underestimate the quality of life benefits
  • We’re still learning
  • What is the case for return-to-office?
  • Moving past gimmicks

Thanks to our podcast sponsor, SpyCloud

Cybercrime doesn’t take breaks. Protect your organization from ransomware, account takeover, and online fraud with SpyCloud. SpyCloud recaptures stolen identity data from breaches, infostealer malware, and phishing attacks that put your business at risk. Teams use SpyCloud’s advanced analytics and powerful automation to stay ahead of attackers. Visit spycloud.com for your free risk report and start disrupting cybercrime today.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Shawn Bowen, VP and deputy CISO - Gaming, Microsoft. Joining us is Adam Fletcher, CSO, Blackstone.

In this episode:

  • Neglected tools drain resources
  • Who’s to blame?
  • Technology is the last step
  • Buying tools to solve business problems

Thanks to our podcast sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Shawn Bowen, VP, Deputy CISO - Gaming, Microsoft. Joining us is Patty Ryan, senior director, CISO, QuidelOrtho.

In this episode:

  • Recognizing humanity
  • Death by a thousand meetings
  • What are we looking for?
  • Find your value

Thanks to our podcast sponsor, GitGuardian

GitGuardian is a Code Security Platform that caters to the needs of the DevOps generation. It provides a wide range of code security solutions, including Secrets Detection, Infra as Code Security, and Honeytoken, all in one place. A leader in the market of secrets detection and remediation, its solutions are already used by hundreds of thousands of developers in all industries. Try now gitguardian.com.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Joining us is Davi Ottenheimer, vp, trust and digital ethics, Inrupt. Sir Tim Berners-Lee co-founded Inrupt to provide enterprise-grade software and services for the Solid Protocol. You can find their open positions here.

In this episode:

  • LLMs lack integrity controls
  • A valid criticism
  • Doubts in self-policing AI
  • New tech, familiar problems

Thanks to our podcast sponsor, Concentric AI

Concentric AI’s DSPM solution automates data security, protecting sensitive data in real-time. Our AI-driven solution identifies, classifies, and secures on-premises and cloud data to reduce risk across your enterprise. Seamlessly integrated with tools like Microsoft Copilot, Concentric AI empowers your team to innovate securely and maintain compliance all while eliminating manual data protection tasks.

Ready to put RegEx and trainable classifiers in the rear view mirror? Contact Concentric AI today!

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Joining us is Dennis Pickett, vp, CISO, Westat.

In this episode:

  • Not all education requires tests
  • Understand your users
  • Building reflexes
  • An ounce of prevention

Thanks to our podcast sponsor, Concentric AI

Concentric AI’s DSPM solution automates data security, protecting sensitive data in real-time. Our AI-driven solution identifies, classifies, and secures on-premises and cloud data to reduce risk across your enterprise. Seamlessly integrated with tools like Microsoft Copilot, Concentric AI empowers your team to innovate securely and maintain compliance all while eliminating manual data protection tasks.

Ready to put RegEx and trainable classifiers in the rear view mirror? Contact Concentric AI today!

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Russell Spitler, CEO and co-founder, Nudge Security.

In this episode:

  • Defining responsibilities
  • Understanding the problem
  • A different role for security
  • Focus on the data

Thanks to our podcast sponsor, Nudge Security

Get a full inventory of all SaaS accounts ever created by anyone in your org, in minutes, along with automated workflows to scale SaaS security and governance. No agents, browser plug-ins or network changes required. Start today with a free 14-day trial.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our guest, Adam Arellano, vp, enterprise cybersecurity, PayPal.

In this episode:

  • Accounting for mindset
  • The importance of ethics
  • A matter of incentives
  • Understanding what is teachable

Thanks to our podcast sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Nick Muy, CISO, Scrut Automation.

In this episode:

  • Segment and test
  • Focus on you
  • Embrace the risk lifecycle
  • Not all vendors are the same

Thanks to our podcast sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Our best-in-class features like process automation, AI, and 75+ native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit www.scrut.io to learn more or schedule a demo.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining me is our guest, Sherron Burgess, CISO, BCD Travel.

In this episode:

  • Disingenuous claims rub everyone the wrong way.
  • Don’t put the CISO behind the 8-ball
  • The sales hustle
  • They didn’t understand the assignment

Thanks to our podcast sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Our best-in-class features like process automation, AI, and 75+ native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit www.scrut.io to learn more or schedule a demo.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and John Underwood, vp, information security, Big 5 Sporting Goods. Joining us is our guest, Mike Lockhart, CISO, EagleView.

In this episode:

  • Marketing versus strategy
  • A distinction without a difference?
  • Terminology follows function
  • Security convergence

Thanks to our podcast sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Our best-in-class features like process automation, AI, and 75+ native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit www.scrut.io to learn more or schedule a demo.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Joining us is our sponsored guest Rob Allen, chief product officer, ThreatLocker.

In this episode:

  • Can you retrofit zero trust?
  • The business case for deny by default
  • Seizing an opportunity
  • Zero trust doesn’t stand alone

Thanks to our podcast sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Joining us is Bil Harmer, operating partner and CISO, Craft Ventures.

In this episode:

  • A time and a place for Field CISOs
  • This isn’t a new role
  • Consulting the Field CISO
  • Words mean things

Thanks to our podcast sponsor, Cyera

Cyera’s AI-powered data security platform gives companies visibility over their sensitive data, context over the risk it represents, and actionable, prioritized remediation guidance.
 As a cloud-native, agentless platform, Cyera provides holistic data security coverage across SaaS, PaaS, IaaS and On-premise environments. Visit www.cyera.io to learn more.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Joining us is Jim Bowie, CISO, Tampa General Hospital.

In this episode:

  • The goal is to connect to the business
  • The hard truth about soft skills
  • Balancing risk
  • Looking beyond communication

Thanks to our podcast sponsor, SeeMetrics

SeeMetrics automates cybersecurity metrics programs, continuously measuring and helping prioritize risks based on context. SeeMetrics unifies siloed data from your security stack and offers hundreds of ready-to-use metrics. Once connected with SeeMetrics, security teams reduce risk, minimize exposure and optimize performance while eliminating tedious repetitive manual work.

Ready to automate your security programs? start connecting your environment at seemetrics.co

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Christina Shannon, CIO, KIK Consumer Products. Joining us is Andrew Cannata, CISO, Primo Water.

In this episode:

  • The lure of an IPO is debatable
  • Does an IPO make you a target or just more vulnerable?
  • M&A changes your context
  • Ambiguity creates risk

Thanks to our podcast sponsor, Cyera

Cyera’s AI-powered data security platform gives companies visibility over their sensitive data, context over the risk it represents, and actionable, prioritized remediation guidance.
 As a cloud-native, agentless platform, Cyera provides holistic data security coverage across SaaS, PaaS, IaaS and On-premise environments. Visit www.cyera.io to learn more.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Shirley Salzman, CEO and co-founder, SeeMetrics.

In this episode:

  • Finding the purpose in metrics
  • Using metrics to answer business questions
  • Speaking to your audience
  • Communication is a two-way street

Thanks to our podcast sponsor, SeeMetrics

SeeMetrics automates cybersecurity metrics programs, continuously measuring and helping prioritize risks based on context. SeeMetrics unifies siloed data from your security stack and offers hundreds of ready-to-use metrics. Once connected with SeeMetrics, security teams reduce risk, minimize exposure and optimize performance while eliminating tedious repetitive manual work.

Ready to automate your security programs? start connecting your environment at seemetrics.co.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Joining us is our sponsored guest, Adam Bateman, CEO, Push Security.

The SaaS attacks matrix community resource mentioned by Adam in the episode can be found here.

Editorial note: Geoff Belknap is an advisor to Push Security.

In this episode:

  • Where are we going wrong
  • Finding the missing pieces
  • Protecting an expanding border
  • It starts with understanding risk

Thanks to our podcast sponsor, Push Security

Prevent, detect and respond to identity attacks using Push Security’s browser agent. Enable Push’s out-of-the-box controls or integrate Push with your SIEM, XDR and SOAR. Block phishing attacks, detect session hijacking and stop SSO passwords being exposed. Find out what else the Push browser agent can do at pushsecurity.com.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Lamont Orange, CISO, Cyera.

In this episode:

  • The data security check has come due
  • Putting data security at the heart of defense in depth
  • Automation is key
  • You need to know what you’re protecting

Thanks to our podcast sponsor, Cyera

Cyera’s AI-powered data security platform gives companies visibility over their sensitive data, context over the risk it represents, and actionable, prioritized remediation guidance.
 As a cloud-native, agentless platform, Cyera provides holistic data security coverage across SaaS, PaaS, IaaS and On-premise environments. Visit www.cyera.io to learn more.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Christina Shannon, CIO, KIK Consumer Products. Joining us is our guest, Tomer Gershoni, CSO, Zoominfo.

In this episode:

  • Moving beyond technology
  • The art of a CISO
  • CISOs always operate in context
  • Elevating the CISO conversation

Thanks to our podcast sponsor, SeeMetrics

SeeMetrics automates cybersecurity metrics programs, continuously measuring and helping prioritize risks based on context. SeeMetrics unifies siloed data from your security stack and offers hundreds of ready-to-use metrics. Once connected with SeeMetrics, security teams reduce risk, minimize exposure and optimize performance while eliminating tedious repetitive manual work.

Ready to automate your security programs? start connecting your environment at seemetrics.co

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Yaron Levi, CISO, Dolby. Joining us is our guest, Neil Watkins, svp technology and cybersecurity services, i3 Verticals.

In this episode:

  • Visibility doesn’t matter without context
  • Not all visibility is created equal
  • Don’t forget to bring people into the loop
  • Remediation doesn’t scale with more visibility

Thanks to our podcast sponsor, GitGuardian

GitGuardian is a Code Security Platform that caters to the needs of the DevOps generation. It provides a wide range of code security solutions, including Secrets Detection, Infra as Code Security, and Honeytoken, all in one place. A leader in the market of secrets detection and remediation, its solutions are already used by hundreds of thousands of developers in all industries. Try now gitguardian.com

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining me is our guest, Sasha Pereira, vp of infrastructure and CISO, WASH.

In this episode:

  • Is working the help desk a great place to get entry level cyber security skills?
  • So why is it so often overlooked or even looked down upon?
  • What kind of experience do you need?
  • What is the ideal path to break into the cybersecurity industry?

Thanks to our podcast sponsor, Push Security!

Prevent, detect and respond to identity attacks using Push Security’s browser agent. Enable Push’s out-of-the-box controls or integrate Push with your SIEM, XDR and SOAR.

Block phishing attacks, detect session hijacking and stop SSO passwords being exposed. Find out what else the Push browser agent can do at pushsecurity.com.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining us is our guest, Russ Ayers, svp of cyber & deputy CISO, Equifax.

In this episode:

  • Are we seeing AI and LLM rapidly push into what was science fiction into production?
  • What happens as our ability to generate realistic sound, video, and images opens the obvious door for indistinguishable fakes from the real thing?
  • How do we keep up as security professionals?
  • What are the security implications for this tech hitting the consumer market?

Thanks to our podcast sponsor, Sonrai Security

A one-click solution that removes excessive permissions and unused services, quarantines unused identities, and restricts specific regions within the cloud. Later, maintain this level of security by automatically enforcing policies as new accounts, roles, permissions, and services are added to your environment. Start a free trial today! sonrai.co/ciso

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Vivek Ramachandran, founder, SquareX.

In this episode:

  • Are secure web gateways still an effective tool in the enterprise?
  • As the browser has changed a lot in the last decade, are Secure Web Gateways - SWGs still keeping up?
  • Why is this a problem?
  • Does anyone have a better solution?

Thanks to our podcast sponsor, SquareX

SquareX helps organizations detect, mitigate and threat-hunt web attacks happening against their users in real-time, including but not limited to malicious sites, files, scripts, and networks. Find out more at sqrx.com.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining me is our guest Richard Stiennon, chief research analyst, IT-Harvest.

In this episode:

In this episode:

  • Why do so many vendors claim to offer zero-trust solutions?
  • Is that framework even applicable to some product categories?
  • Do your eyes roll when you hear "zero trust solution"?
  • What do most people think it is, and what’s the reality?

Thanks to our podcast sponsor, SquareX

SquareX helps organizations detect, mitigate and threat-hunt web attacks happening against their users in real-time, including but not limited to malicious sites, files, scripts, and networks. Find out more at sqrx.com.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining us is our sponsored guest, Sandy Bird, co-founder and CTO, Sonrai Security.

In this episode:

  • Why does scaling least privilege in the cloud remain challenging?
  • Is throwing more people at the problem feasible?
  • How are you managing it?
  • What aspects haven’t been considered?

Thanks to our podcast sponsor, Sonrai Security

A one-click solution that removes excessive permissions and unused services, quarantines unused identities, and restricts specific regions within the cloud. Later, maintain this level of security by automatically enforcing policies as new accounts, roles, permissions, and services are added to your environment. Start a free trial today! sonrai.co/ciso

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining me is our guest, Emily Heath, general partner, Cyberstarts.

In this episode:

  • How do CISOs feel about sales pitches?
  • Do they have legitimate complaints?
  • When do these legitimate complaints cross the line to sounding entitled?
  • Do CISOs need to show a little more empathy to sales?

Thanks to our podcast sponsor, SquareX

SquareX helps organizations detect, mitigate and threat-hunt web attacks happening against their users in real-time, including but not limited to malicious sites, files, scripts, and networks. Find out more at sqrx.com.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining me is our sponsored guest, Mackenzie Jackson, developer advocate, GitGuardian.

In this episode:

  • How to manage data leaks outside your perimeter?
  • When data leaks increasingly come from third-parties, what can you do to protect your organization?
  • How do we even begin to address this problem?
  • Is there a one size fits all fix?

Thanks to our podcast sponsor, GitGuardian

GitGuardian is a Code Security Platform that caters to the needs of the DevOps generation. It provides a wide range of code security solutions, including Secrets Detection, Infra as Code Security, and Honeytoken, all in one place. A leader in the market of secrets detection and remediation, its solutions are already used by hundreds of thousands of developers in all industries. Try now gitguardian.com

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining me is our guest, Phil Davis, attorney, healthcare cybersecurity and privacy, Hall Render.

In this episode:

  • In today's current climate, is the role of the CISO still worth it?
  • Does the position carry a lot of potential liability?
  • Do the upsides still outweigh the risks?
  • Do CISOs tend to have more responsibility than authority?

Thanks to our podcast sponsor, Sonrai Security

A one-click solution that removes excessive permissions and unused services, quarantines unused identities, and restricts specific regions within the cloud. Later, maintain this level of security by automatically enforcing policies as new accounts, roles, permissions, and services are added to your environment.

Start a free trial today! sonrai.co/ciso

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining me is our guest, Paul Connelly, former CISO, HCA HealthcareGot feedback?

In this episode:

  • How important is onboarding new cyber talent?
  • Does it set the tone for their tenure with your organization?
  • What should CISOs do to make sure onboarding is effective for both sides?
  • What are the mistakes CISOs should avoid, and what are the best ways to excel?

Thanks to our podcast sponsor, OffSec

OffSec helps companies like Cisco, Google, and Salesforce upskill cybersecurity talent through comprehensive training and resources. With programs ranging from red team and blue team training and more, your team will be ready to face real-world threats. Request a free trial for your team to explore OffSec’s learning library and cyber range.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post Monte Pedersen of The CDA Group for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining us is our guest, Jerry Davis, division director for cyber defense at Truist Bank.

In this episode:

  • Why does advancing your career require more than just technical skills?
  • Does it require you to build relationships within your organizations, particularly with your boss?
  • How can you consciously build these relationships with an eye to leveling up your career?
  • How do you develop soft skills?

Thanks to our podcast sponsor, OffSec

OffSec helps companies like Cisco, Google, and Salesforce upskill cybersecurity talent through comprehensive training and resources. With programs ranging from red team and blue team training and more, your team will be ready to face real-world threats. Request a free trial for your team to explore OffSec’s learning library and cyber range.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining me is our sponsored guest, Spencer Thompson, CEO, Prelude.

In this episode:

  • Why does it take so long to integrate new tools and get them up to speed?
  • Are we always in a state where we are always lacking readiness?
  • What should we be measuring?
  • Do we focus too much on singular events?

Thanks to our podcast sponsor, Prelude

Prelude Detect is the world's only production-scale detection and response testing platform. Automatically transform your threat intelligence into validated detections and preventions in less than five minutes. Integrate with CrowdStrike, Microsoft Defender, SentinelOne, and more to enable machine speed detection and response engineering 🏎️ Learn more at preludesecurity.com.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining me is our guest, Ron Gula, president and co-founder, Gula Tech Adventures.

In this episode:

  • Why is it so darn expensive to get any training on the defender side?
  • Why is there a mountain of free education for red teaming?
  • Shouldn’t blue team training should be free or less expensive as well?
  • Is this the firewall that's preventing us from having all those cyber experts we so desperately need?

Thanks to our podcast sponsor, Query

Query Federated Search gets to your security relevant data wherever it is - in data lakes, security tools, cloud services, SIEMs, or wherever. Query searches and normalizes data for use in security investigations, threat hunting, incident response, and everything you do. And we plug into Splunk. Visit query.ai.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining me is our guest, Ben Sapiro, head of global cyber security services, Manulife.

In this episode:

  • Why do we see a dearth of CISOs listed in executive leadership?
  • Is this just a factor of company reporting structure?
  • Or do CISOs really not have a seat at the table with the business?
  • How do we convince the C-suite?

Thanks to our podcast sponsor, Query

Query Federated Search gets to your security relevant data wherever it is - in data lakes, security tools, cloud services, SIEMs, or wherever. Query searches and normalizes data for use in security investigations, threat hunting, incident response, and everything you do. And we plug into Splunk. Visit query.ai.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Matt Eberhart, CEO, Query.

In this episode:

  • Isn't the whole point of a single pane of glass making sense of your data?
  • But when these dashboards are limited to a single platform, how useful are they?
  • Does it seem like all they've led to is more browser tabs or more monitors crowding your analysts?
  • We know we want to take action based on our data, so how do we get there?

Thanks to our podcast sponsor, Query

Query Federated Search gets to your security relevant data wherever it is - in data lakes, security tools, cloud services, SIEMs, or wherever. Query searches and normalizes data for use in security investigations, threat hunting, incident response, and everything you do. And we plug into Splunk. Visit query.ai.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining me is my guest, Mario Trujillo, staff attorney, Electronic Frontier Foundation.

In this episode:

  • Data is the life blood of an organization but what happens when you collect too much?
  • Do you put risk on both your organization and for any individuals that data belongs too?
  • Is it still wise to collect as much data as possible?
  • How can CISOs embrace data minimization that doesn't clash with the needs of the business?

Thanks to our podcast sponsor, Material Security

Material Security is purpose-built to stop attacks and reduce risk across Microsoft 365 and Google Workspace with unified cloud email security, data loss prevention, and posture management. Learn more at material.security.

View Details

All links and images for this episode can be found on CISO Series.

The Verizon DBIR found that about half of all breaches involved legitimate credentials. It’s a huge attack surface that we’re only starting to get a handle of.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining me is our guest, Adam Koblentz, field CTO, Reveal Security.

In this episode:

  • Where are we in terms of monitoring anomalous behavior of our users?
  • Why are we still struggling to understand what happens after threat actors are in our networks?
  • How are new AI-based tools helping us to scale efforts?
  • What's working and where do we need to improve?

Thanks to our podcast sponsor, Reveal Security

Reveal Security ITDR detects identity threats - post authentication - in and across SaaS applications and cloud services. Powered by unsupervised machine learning, it continuously monitors and validates the behavior of trusted human users, APIs and other entities, accurately detecting anomalies that signal an in-progress identity threat. Visit reveal.security

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining me is our guest, Mike Levin, deputy CISO, 3M.

In this episode:

  • Why do security startups fail?
  • All startups are an inherently risky proposition, but what are the specific challenges for startups in our industry?
  • What's unique about cybersecurity startups?
  • What's the most common reason you've seen a cyber startup not succeed?

Thanks to our podcast sponsor, RevealSecurity!

Reveal Security ITDR detects identity threats - post authentication - in and across SaaS applications and cloud services. Powered by unsupervised machine learning, it continuously monitors and validates the behavior of trusted human users, APIs and other entities, accurately detecting anomalies that signal an in-progress identity threat. Visit reveal.security

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining me is our guest, Derek Fisher, Executive director of product security, JPMorgan.

In this episode:

  • A security program shouldn't stop at compliance, but that doesn't mean we should undervalue it, right?
  • Why are we so quick to dismiss compliance as simple check boxes?
  • Why is compliance important and why is it often getting a bad name these days?
  • What are the elements that make a great solution?

Thanks to our podcast sponsor, RevealSecurity!

Reveal Security ITDR detects identity threats - post authentication - in and across SaaS applications and cloud services. Powered by unsupervised machine learning, it continuously monitors and validates the behavior of trusted human users, APIs and other entities, accurately detecting anomalies that signal an in-progress identity threat. Visit reveal.security

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining me is our guest, Alexandra Landegger, Executive Director and CISO, Collins Aerospace.

In this episode:

  • Why do mergers and acquisitions always present challenges to an organization?
  • When it comes to cybersecurity, how involved should a CISO be before AND after an acquisition?
  • Can cybersecurity considerations make or break a deal?
  • What skills did you find yourself flexing with your first M&A experience?

Thanks to our podcast sponsor, Aphinia!

Join Aphinia, a professional tribe of superheroes fighting cybercriminals. If you are a CISO, VP or a Director of cybersecurity, get instant free access to thousands of your peers, career advice, networking opportunities, consulting gigs and more. Join the good guys’ team because the only way to succeed is together: https://aphinia.com/#signup_form

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Richard Ford, CTO, Praetorian.

In this episode:

  • When did we all agree that red teaming was about validating security?
  • Does it seem like increasingly red teaming is a catch all term for a whole lot of testing that isn't clearly defined?
  • Is this making it hard to see its value?
  • Can moving red teaming upstream be more valuable to your organization?

Thanks to our podcast sponsor, Praetorian

Praetorian helps companies adopt a prevention-first cybersecurity strategy by actively uncovering vulnerabilities and minimizing potential weaknesses before attackers can exploit them.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our guest, Adam Glick, CISO, PSG.

In this episode:

  • Vendors need to reach out to CISOs, but what does a successful approach look like?
  • Do vendors often spray and pray with outreach, rather than doing a bare minimum of research?
  • What else can vendors do to try to create meaningful outreach to CISOs?
  • How do you like security sales professionals to build a relationship with you?

Thanks to our podcast sponsor, Praetorian

Praetorian helps companies adopt a prevention-first cybersecurity strategy by actively uncovering vulnerabilities and minimizing potential weaknesses before attackers can exploit them.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining me is our guest, Erik Decker, CISO, Intermountain Health.

In this episode:

  • Why are we all struggling trying to manage third-party risk?
  • Why do the hated questionnaires seem like compliance checkbox efforts?
  • Does anyone believe it reduces risk?
  • What's the right approach and how do you strike the right balance?

Thanks to our podcast sponsor, Praetorian

Praetorian helps companies adopt a prevention-first cybersecurity strategy by actively uncovering vulnerabilities and minimizing potential weaknesses before attackers can exploit them.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining me is our sponsored guest, Trevor Hilligoss, senior director of security research, SpyCloud.

In this episode:

  • What are the things that raise red flags that you're about to experience an attack?
  • What signals set off your Spidey sense that things could go sideways?
  • What are the early warning signs an attack is underway?
  • Did you learn anything new?

Thanks to our podcast sponsor, SpyCloud

Get ahead of ransomware attacks by acting on a common precursor: infostealer malware. SpyCloud recaptures what’s stolen from infostealer-infected systems, and alerts your team to take action before compromised authentication data can be used by criminals to target your business. Get our latest research and check your malware exposure at spycloud.com/ciso.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining me is our guest, David Christensen, VP, CISO, PlanSource.

In this episode:

  • How do you actually focus your patching efforts on the vulnerabilities that are seen as universally holding the most risk?
  • With limited resources, is it possible to "patch all the things"?
  • How do we focus patching efforts to fix the most vital issues quickly?
  • What are the risks we’re dealing with?

Thanks to our podcast sponsor, SpyCloud

Get ahead of ransomware attacks by acting on a common precursor: infostealer malware. SpyCloud recaptures what’s stolen from infostealer-infected systems, and alerts your team to take action before compromised authentication data can be used by criminals to target your business. Get our latest research and check your malware exposure at spycloud.com/ciso.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining us is our guest, Jerich Beason, CISO, WM.

In this episode:

  • Does generative AI come with a new set of risks?
  • How can we address these risks to take advantage of its benefits?
  • How do we approach a much desired technology we're not so sure how we should secure?
  • How can we take what we've learned from past technological advances and apply it to mitigate risks with generative AI?

Thanks to our podcast sponsor, SpyCloud

Get ahead of ransomware attacks by acting on a common precursor: infostealer malware. SpyCloud recaptures what’s stolen from infostealer-infected systems, and alerts your team to take action before compromised authentication data can be used by criminals to target your business. Get our latest research and check your malware exposure at spycloud.com/ciso.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining us is our sponsored guest, Himaja Motheram, Censys.

In this episode:

  • How can one create a security program around unknown problems?
  • Don’t we know a lot of the things we lack visibility into that can cause security issues?
  • But what about the things you don't even know about in the first place?
  • Will that thing we don't even know to look at, ever cause a security issue?

Thanks to our podcast sponsor, Censys

Censys is the leading Internet Intelligence Platform for Threat Hunting and Exposure Management. We provide the most comprehensive, accurate, and up-to-date map of the internet, which scans 45x more services than the nearest competitor across the world’s largest certificate database (>10B). Learn more at www.censys.com.

View Details

All links and images for this episode can be found on CISO Series.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Russell Spitler, CEO and co-founder, Nudge Security.

In this episode:

  • Are businesses walking a tightrope with generative AI?
  • How can organizations implement generative AI responsibly?
  • What can we learn from previous transitions that can help us responsibly bring generative AI into the workplace milieu?
  • What else are we missing?

Thanks to our podcast sponsor, Nudge Security

Nudge Security provides complete visibility of every SaaS and cloud account ever created by anyone in your org, in minutes. No agents, browser plug-ins or network proxies required. With this visibility, you can discover shadow IT, manage your SaaS attack surface, secure SaaS access, and respond effectively to SaaS breaches.

View Details

All links and images for this episode can be found on CISO Series.

In increasingly complex technical defenses, threat actors frequently target the human element. This makes them a top attack vectors, but are they actually the weak leak in your defenses?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining us is our guest, Christina Shannon, CIO, KIK Consumer Products.

Thanks to our podcast sponsor, SPHERE

SPHERE is the Identity Hygiene pioneer. It closes the loop on ownership, certification, and remediation challenges through an automated remediation process. By working with the IAM and PAM solutions organizations have in place, SPHEREboard automates discovery and remediation on an ongoing basis. Learn more at sphereco.com!

In this episode:

  • Threat actors frequently target the human element, but are they actually the weak leak in your defenses?
  • Have we been treating humans wrong in our environment?
  • Is the blame on security professionals for failing to design security systems to set humans up for success?
  • Is it disingenuous to presume that cybersecurity would be perfect if not for users?

View Details

All links and images for this episode can be found on CISO Series.

We often talk about the contradiction of seemingly entry-level security jobs requiring years of experience. But maybe that's because entry-level jobs don't actually exist.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining us this week is our guest Jay Wilson, CISO, Insurity.

Thanks to our podcast sponsor, SlashNext

SlashNext Complete delivers zero-hour protection for how people work today across email, mobile, and browser apps. With SlashNext’s generative AI to defend against advanced business email compromise, smishing, spear phishing, executive impersonation, and financial fraud, your people are always protected anywhere they work. Request a demo today.

In this episode:

  • What's “entry level” in cybersecurity and does it even exist?
  • What causes the contradiction of seemingly entry-level security jobs requiring years of experience?
  • Why does it seem like there are still no entry level jobs?
  • How do job candidates get creative with their experience to get a foot in the door?

View Details

All links and images for this episode can be found on CISO Series.

The Securities and Exchange Commission issued new cyber rules. What do these new rules mean for CISOs and will they ultimately improve our cybersecurity posture?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our guest, Jamil Farshchi, CISO, Equifax.

Thanks to our podcast sponsor, Nudge Security

Nudge Security provides complete visibility of every SaaS and cloud account ever created by anyone in your org, in minutes. No agents, browser plug-ins or network proxies required. With this visibility, you can discover shadow IT, manage your SaaS attack surface, secure SaaS access, and respond effectively to SaaS breaches.

In this episode:

  • The Securities and Exchange Commission issued new cyber rules.
  • What do these new rules mean for CISOs and will they ultimately improve our cybersecurity posture?
  • Are these rules something to celebrate, or are they just going to make a CISOs compliance efforts even more difficult?
  • For those companies who actually follow the guidance, will this step up their cyber game considerably?

View Details

All links and images for this episode can be found on CISO Series.

Are trade shows like RSA getting so big that there's not enough economic value for a CISO to attend? Or do these events have enough industry gravity to justify the spend?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining us is our special guest Lee Parrish, CISO, Newell Brands.

Thanks to our podcast sponsor, Censys

In this episode:

  • Everyone sees value in security professionals coming together, but what specific value does a huge expo like RSA deliver?
  • Are trade shows like RSA getting so big that there's not enough economic value for a CISO to attend?
  • Or do these events have enough industry gravity to justify the spend?
  • Will FOMO continue to force vendors to sponsor big shows like RSA?

View Details

All links and images for this episode can be found on CISO Series.

Work from home flourished during the pandemic. Many workers love it and don't want to go back. Some organizations are pushing for a return to the office. Is in-office work necessary to improve productivity and cybersecurity posture?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining us for the episode is our guest, Shawn Bowen, CISO, World Kinect Corporation.

Thanks to our podcast sponsor, Nudge Security

Nudge Security provides complete visibility of every SaaS and cloud account ever created by anyone in your org, in minutes. No agents, browser plug-ins or network proxies required. With this visibility, you can discover shadow IT, manage your SaaS attack surface, secure SaaS access, and respond effectively to SaaS breaches.

In this episode:

  • Is in-office work necessary to improve productivity and cybersecurity posture?
  • Is this push for return to office just an effort for managers to return to the "good 'ole days" with no other rationale?
  • So technology can be great from anywhere, but people cannot?
  • Does successful work from home require a mature approach to leadership?

View Details

All links and images for this episode can be found on CISO Series.

Large language models and generative AI are today's disruptive technology. This is not the first time companies just want to ban a new technology that everyone loves. Yet, we're doing it all over again. Whether its ChatGPT or BYOD, people are going to use desirable new tech. So if our job isn't to stop it, how do we secure it?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining us is our special guest, Carla Sweeney, SVP, InfoSec, Red Ventures.

Thanks to our podcast sponsor, Censys

Censys is the leading Internet Intelligence Platform for Threat Hunting and Exposure Management. We provide the most comprehensive, accurate, and up-to-date map of the internet, which scans 45x more services than the nearest competitor across the world’s largest certificate database (>10B). Learn more at www.censys.com.

In this episode:

  • Whether its ChatGPT or BYOD, people are going to use desirable new tech. So if our job isn't to stop it, how do we secure it?
  • Are tools like ChatGPT so different from what we've seen before that we can't apply lessons already learned?
  • What risks are we solving for with it and where do we go from there?
  • Is this just a security issue?

View Details

All links and images for this episode can be found on CISO Series.

What do the people least in the know about cyber, want to know? What are they asking?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining us is our special guest, Caitlin Sarian, AKA cybersecuritygirl on TikTok.

Thanks to our podcast sponsor, DataBee from Comcast Technology Solutions

DataBee™, from Comcast Technology Solutions, is a cloud-native security, risk and compliance data fabric platform that transforms your security data chaos into connected outcomes. Built by security professionals for security professionals, DataBee enables users to examine the past, react to the present, and protect the future of the business.

In this episode:

  • What do the people least in the know about cyber, want to know? What are they asking?
  • How important is it to understand what concerns the average person?
  • Are these reasonable concerns or do you think they're directed by media pressure?
  • How do regular, everyday people know what is safe and best practices without a clear path or studying cybersecurity in depth?

View Details

All links and images for this episode can be found on CISO Series.

A security data lake, a data repository of everything you need to analyze and get analyzed sounds wonderful. But priming that lake, and stocking it with the data you want to get the insights you need is a more difficult task than it seems.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining us is our sponsored guest, Matt Tharp, Head of Field Engineering, Comcast DataBee.

Thanks to our podcast sponsor, Comcast Technology Solutions

In this episode:

  • What exactly is a data lake?
  • How are people thinking about and handling the risks?
  • If you want security data lakes to be successful, what customer problem are you trying to solve?
  • How can you make it both dead simple to use AND highly effective?

View Details

All links and images for this episode can be found on CISO Series.

A threat intelligence program sounds like a sound effort in any security program. But, can you pull it off? There are so many phases to execute properly. Blow it with any one of them and your threat intelligence effort is moot.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us today is our special guest Jon Oltsik, distinguished analyst and fellow, Enterprise Strategy Group.

Thanks to our podcast sponsor, Comcast

DataBee™, from Comcast Technology Solutions, is a cloud-native security, risk and compliance data fabric platform that transforms your security data chaos into connected outcomes.

Built by security professionals for security professionals, DataBee enables users to examine the past, react to the present, and protect the future of the business.

In this episode:

  • A threat intelligence program sounds like a sound effort in any security program. But, can you pull it off?
  • Which phase of a threat intelligence program gives you the most trouble, and why?
  • What has been your personal experience, and does it change organization to organization?
  • How do you measure the success of the program to prove the value of the work being done?

View Details

All links and images for this episode can be found on CISO Series.

When you have an incident and you're engulfed by the stress that lasts more than a day, how do you manage and deal with it? And not only how do you manage your stress, but how do you manage everyone else's?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining us is our special guest, Tim Brown, CISO, Solarwinds.

Thanks to our podcast sponsor, Push Security

Do you have visibility of all the SaaS apps your employees are storing corporate data on? Are employees protecting all their accounts against identity-based attacks?

Discover all the SaaS your employees use - including shadow apps and identities - and secure your data. Find out more at pushsecurity.com.

In this episode:

  • When you have an incident and you're engulfed by the stress that lasts more than a day, how do you manage and deal with it?
  • And not only how do you manage your stress, but how do you manage everyone else's?
  • During a major incident, which stress is more difficult to manage? Your own, or those around you?
  • How is this everyone's concern?

View Details

All links and images for this episode can be found on CISO Series.

We all know that our employees need to be more security aware, but what are the methods to get them there? How can we make our employees more security conscious?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest Jack Chapman, vp, threat intelligence, Egress.

Thanks to our podcast sponsor, Egress

Egress helps organization stop email security risks is by addressing both inbound and outbound threats together,. We recognize that people get hacked, make mistakes, and break the rules. Egress's Intelligent Cloud Email Security suite uses patented self-learning technology to detect sophisticated inbound and outbound threats, and protect against data loss. Learn more at egress.com.

In this episode:

  • We all know that our employees need to be more security aware, but what are the methods to get them there?
  • How can we make our employees more security conscious?
  • What does it take to get security to "stick" with your coworkers?
  • Why does security remain so darn difficult?

View Details

All links and images for this episode can be found on CISO Series.

Users have tried to upload sensitive company information and PII, personally identifiable information, into ChatGPT. Those who are successful getting the data in, have now made that data free to all. Will people's misuse of these generative AI programs be our greatest downfall to security and privacy?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining us is our special guest Suha Can, CISO, Grammarly.

Thanks to our podcast sponsor, Opal

Opal is building the next generation of intelligent identity. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower teams to understand and calibrate access end to end, and to build identity security for scale. Learn more by at www.opal.dev.

In this episode:

  • Will people's misuse of these generative AI programs be our greatest downfall to security and privacy?
  • Is AI the problem? Or is poor human judgement the problem?
  • Is it better to get started with any guardrails until setting up a full policy?
  • What are we going to do now?

View Details

All links and images for this episode can be found on CISO Series.

The demand for cybertalent is sky high. It's very competitive to get those people with skills. What if you were to train your staff and give them the skills you want? Essentially, what if you were to grow your own unicorn?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Joining us is our special guest, Jesse Whaley, CISO, Amtrak.

Thanks to our podcast sponsor, Opal

Opal is building the next generation of intelligent identity. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower teams to understand and calibrate access end to end, and to build identity security for scale. Learn more by at www.opal.dev.

In this episode:

  • What if you were to train your staff and give them the skills you want?
  • What if you were to grow your own unicorn?
  • What’s the best way to grow your staff?
  • How do you figure out the right mix of talent and prioritize the hiring, training, on the job, and other experiences?

View Details

All links and images for this episode can be found on CISO Series.

What are we doing to improve access management? Make it too loose and it's the number one way organizations get breached. Put on too many controls and now you've got irritated users just trying to do their job. How does each organization find their sweet spot?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our sponsored guest Paul Guthrie (@pguthrie), information security officer, Blend.

Thanks to our podcast sponsor, Opal

Opal is building the next generation of intelligent identity. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower teams to understand and calibrate access end to end, and to build identity security for scale. Learn more by at www.opal.dev

In this episode:

  • What is the one most significant action you’ve taken to improve access management?
  • What are we doing to improve access management?
  • What is the correct balance between too many controls and not enough?
  • How does each organization find their sweet spot?

View Details

All links and images for this episode can be found on CISO Series.

With the growth of business-led IT, does SaaS security need to be a specific focus in a CISO’s architectural strategy?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our guest is Steve Zalewski who also hosts Defense in Depth.

Thanks to our podcast sponsor, AppOmni

*Do you know which 3rd party apps are connected to your SaaS platforms? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk.

Get visibility to all 3rd party apps — and their level of data access — with AppOmni. Visit AppOmni.com to request a free risk assessment.*

In this episode:

  • With the growth of business-led IT, does SaaS security need to be a specific focus in a CISO’s architectural strategy?
  • Is the problem the architecture of the applications themselves or the fact that a non-security group is bringing these applications online? Is it both?
  • Is this problem solvable?
  • What technical controls can you put in place to mitigate risk from apps you deem risky?

View Details

All links and images for this episode can be found on CISO Series.

When it comes to data, compliance, and reducing risk, where are we gaining control? Where are we losing control? And what are we doing about that?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. We welcome our sponsored guest Amer Deeba, CEO and Co-founder, Normalyze.

Thanks to our podcast sponsor, Normalyze

Normalyze is a cloud data security platform that continuously discovers sensitive data and their access paths across your cloud environments. Normalyze provides the ability to analyze, prioritize and respond to data threats to prevent damaging data breaches.

Discover, visualize, and secure your cloud data in minutes with Normalyze Freemium.

In this episode:

  • When it comes to data, compliance, and reducing risk, where are we gaining control?
  • Where are we losing control? And what are we doing about that?
  • Is "losing control" inevitable?
  • Is SaaS really extremely difficult to work with at scale?

View Details

All links and images for this episode can be found on CISO Series.

If you're struggling to get your first job in security or you're trying to get back into the industry after being laid off, you need to lean on your security community. But like networking, you should find it before you need it.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski.

Thanks to our podcast sponsor, Egress

Egress helps organization stop email security risks is by addressing both inbound and outbound threats together,. We recognize that people get hacked, make mistakes, and break the rules. Egress's Intelligent Cloud Email Security suite uses patented self-learning technology to detect sophisticated inbound and outbound threats, and protect against data loss. Learn more at egress.com.

In this episode:

  • Are you struggling to get your first job in security or trying to get back into the industry after being laid off?
  • What is the importance of building your security community network ?
  • What should you look for in a community?
  • What should you expect to put into it, and what should you expect to get back?

View Details

All links and images for this episode can be found on CISO Series.

What should a cyber job description require, and what shouldn't it? What's reasonable and not reasonable?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our guest is Rob Duhart (@robduhart), deputy CISO, Walmart.

Thanks to our podcast sponsor, Normalyze

Normalyze is a cloud data security platform that continuously discovers sensitive data and their access paths across your cloud environments. Normalyze provides the ability to analyze, prioritize and respond to data threats to prevent damaging data breaches.

Discover, visualize, and secure your cloud data in minutes with Normalyze Freemium.

In this episode:

  • What should a cyber job description require, and what shouldn't it? What's reasonable and not reasonable?
  • Do these completely unrealistic job descriptions hurt the entire industry?
  • What is it we need to put in a cyber job description, and what do we need to leave out?
  • Who’s losing out here?

View Details

All links and images for this episode can be found on CISO Series.

Since so much technology today is not launched by the IT department, but by business units themselves. How do security professionals engage with business and application owners and have a conversation about security policy and procedures?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our sponsored guest Harold Byun (@haroldnhoward), chief product officer, AppOmni.

Thanks to our podcast sponsor, AppOmni

Do you know which 3rd party apps are connected to your SaaS platforms? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk.
Get visibility to all 3rd party apps — and their level of data access — with AppOmni. Visit AppOmni.com to request a free risk assessment.

In this episode:

  • What's your experience talking about security policy and procedures with business and application owners?
  • How do security professionals engage with business and application owners?
  • How do they have a conversation about security policy and procedures?
  • Is there anything you learned that you didn't realize before?

View Details

All links and images for this episode can be found on CISO Series.

There are millions of cybersecurity jobs open. Over time, that number has just been growing. What we're doing now does not seem to be working. So what's it going to take to fill all these jobs quickly?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Rich Gautier, former CISO for the U.S. Department of Justice, Criminal Division.

Thanks to our podcast sponsor, Brinqa

Understand your cyber assets, prioritize vulnerabilities, automate remediation, and continuously monitor cyber hygiene across the entire attack surface — infrastructure, applications and cloud — with Brinqa. See how at brinqa.com.

In this episode:

  • There are millions of cybersecurity jobs open. What's it going to take to fill all these jobs quickly?
  • Are job description requirements partially to blame for holding back the industry from tapping into greater diversity of expertise?
  • Is it better off if you hire, train, culturally integrate, and reward that person?
  • Does burn out and a steep learning curve keep adding to the problem?

View Details

All links and images for this episode can be found on CISO Series.

How do you create a positive security culture? It's rarely the first concept anyone wants to embrace, yet it's important everyone understands their responsibility. So what do you do, and how do you overcome inevitable roadblocks?

Check out this post and this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our sponsored guest, Jadee Hanson, CISO/CIO for Code42.

Thanks to our podcast sponsor, Code42

Code42 is focused on delivering solutions built with the modern-day collaborative culture in mind. Code42 Incydr tracks activity across computers, USB, email, file link sharing, Airdrop, the cloud and more, our SaaS-based solution surfaces and prioritizes file exposure and data exfiltration events. Learn more at Code42.com.

In this episode:

  • How do you create a positive security culture?
  • Where do we run into struggles when trying to create a positive security culture?
  • Given its importance, why is it rarely the first concept anyone wants to embrace?
  • What do you do, and how do you overcome inevitable roadblocks?

View Details

All links and images for this episode can be found on CISO Series.

All experienced security professionals were at one time very green. Entry level status means risk to your organization. That's if you give them too much access. What can you trust an entry level security professional to do that won't impose unnecessary risk? And how can those green professionals build trust to allow them to do more?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Kemas Ohale, vp, global information security, Lippert.

Thanks to our podcast sponsor, Normalyze

Normalyze is a cloud data security platform that continuously discovers sensitive data and their access paths across your cloud environments. Normalyze provides the ability to analyze, prioritize and respond to data threats to prevent damaging data breaches.
Discover, visualize, and secure your cloud data in minutes with Normalyze Freemium.

In this episode:

  • What can you trust an entry level security professional to do that won't impose unnecessary risk?
  • How can those green professionals build trust to allow them to do more?
  • What can they do with zero experience?
  • How can they graduate upwards?

View Details

All links and images for this episode can be found on CISO Series.

What do we need to do to fix our processes to truly reduce risk and vulnerabilities?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our sponsored guest is Amad Fida (@brinqa), CEO, Brinqa.

Thanks to our podcast sponsor, Brinqa

Understand your cyber assets, prioritize vulnerabilities, automate remediation, and continuously monitor cyber hygiene across the entire attack surface — infrastructure, applications and cloud — with Brinqa. See how at brinqa.com.

In this episode:

  • What do we need to do to fix our processes to truly reduce risk and vulnerabilities?
  • How to work with all departments to improve process, communication, and motivation?
  • Why does security need to be treated as a function of the enterprise risk program?
  • What are the elements that make a great solution?

View Details

All links and images for this episode can be found on CISO Series.

Security professionals talk a lot about the reputational damage from breaches. And it seems logical, but major companies still do get breached and their reputation seems spared. What's the reality of what breaches can do to a company's reputation?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our guest Cecil Pineda, CISO, R1.

Thanks to our podcast sponsor, Brinqa

Understand your cyber assets, prioritize vulnerabilities, automate remediation, and continuously monitor cyber hygiene across the entire attack surface — infrastructure, applications and cloud — with Brinqa. See how at brinqa.com.

In this episode:

  • Security professionals talk a lot about the reputational damage from breaches, so why do companies still get breached?
  • What's the reality of what breaches can do to a company's reputation?
  • Does a breach really result in lasting reputation damage?
  • Are we more accepting of breaches now?

View Details

All links and images for this episode can be found on CISO Series.

Do RFPs or request for proposals work as intended? It seems they're loaded with flaws yet for some organizations who must follow processes, they become necessary evils for both buyers and sellers. What can we do to improve the process?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our guest Keith McCartney (@kmflgator), vp, security and IT, DNAnexus.

Thanks to our podcast sponsor, TrustCloud

TrustCloud is the all-in-one platform to accelerate sales and security reviews, automate compliance efforts, and map contractual liability across your business. Connect with us to learn how you can transform security from a cost center into a profit driver with TrustCloud’s programmatic risk and compliance verification tools.

In this episode:

  • Do RFPs or request for proposals work as intended?
  • Does it seem they're loaded with flaws?
  • Have they become necessary evils for both buyers and sellers?
  • What can we do to improve the process?

View Details

All links and images for this episode can be found on CISO Series.

What are the moves we should be making in cloud to improve our security? What constitutes a good cloud security posture?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Andy Ellis, operating partner, YL Ventures. We welcome our sponsored guest Yoav Alon, CTO, Orca Security.

Thanks to our podcast sponsor, Orca Security

Orca Security is the pioneer of agentless cloud security that is trusted by hundreds of enterprises globally. With continuous first-to-market innovations and expertise, the Orca Platform ensures security teams quickly identify and remediate risks to keep their businesses secure. Connect your first account in minutes by visiting www.orca.security.

In this episode:

  • What does successful cloud security look like?
  • What are the moves we should be making in the cloud to improve our security?
  • What constitutes a good cloud security posture?
  • What should we be measuring when it comes to cloud security?

View Details

All links and images for this episode can be found on CISO Series.

One CISO has had enough of the security vendor marketing emails and cold sales calls. He's blocking them all. But it's not a call to avoid all salespeople. He just doesn't have the time to be a target anymore. So how should vendors engage with such a CISO? And does CISO represent most CISOs today?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our sponsored guest Joy Forsythe, VP, Security, Thrive Global.

Thanks to our podcast sponsor, Code42

Code42 is focused on delivering solutions built with the modern-day collaborative culture in mind. Code42 Incydr tracks activity across computers, USB, email, file link sharing, Airdrop, the cloud and more, our SaaS-based solution surfaces and prioritizes file exposure and data exfiltration events. Learn more at Code42.com.

In this episode:

  • How should vendors engage with CISOs who are tired of being targeted?
  • How can vendors reach CISOs who have had enough of the security vendor marketing emails and cold sales calls?
  • Does CISO represent most CISOs today?
  • Is the sales "system" essentially broken?

View Details

All links and images for this episode can be found on CISO Series.

Do we really need more categories of security products? Every new Gartner magic quadrant complicates the marketplace but at the same time helps us understand the other vectors we need to protect. Do new categories of security products help or hurt the industry?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Corey Elinburg (@celinburg), CISO, CommonSpirit Health.

Thanks to our podcast sponsor, Egress

In this episode:

  • Do we really need more categories of security products?
  • Does it seem like every new Gartner magic quadrant complicates the marketplace but at the same time helps us understand the other vectors we need to protect?
  • Do new categories of security products help or hurt the industry?
  • Does this make it hard to keep up to date on all new products?

View Details

All links and images for this episode can be found on CISO Series.

How can security leaders and how do they go about matching business case to every security action you want to take? Is this the right way to sell security to the board?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our sponsored guest is Sravish Sridhar (@sravish), founder and CEO, TrustCloud.

Thanks to our podcast sponsor, TrustCloud

TrustCloud is the all-in-one platform to accelerate sales and security reviews, automate compliance efforts, and map contractual liability across your business. Connect with us to learn how you can transform security from a cost center into a profit driver with TrustCloud’s programmatic risk and compliance verification tools.

In this episode:

  • How can security leaders best make a case for security?
  • How do you go about matching business cases to every security action you want to take?
  • Is this the right way to sell security to the board?
  • How do you show that security can be aligned to business objectives?

View Details

All links and images for this episode can be found on CISO Series.

Security tools are supposed to do a job. Either they need to alert you, protect you, or remediate an issue. But they don't always work and that's why we have breaches. Who's at fault, the tool or the administrators who configured the tool?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our guest Kenneth Foster (@Kennethrfoster1), vp of IT governance, risk and compliance at FLEETCOR.

Thanks to our podcast sponsor, AppOmni

Do you know which 3rd party apps are connected to your SaaS platforms? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk. Get visibility to all 3rd party apps — and their level of data access — with AppOmni. Visit AppOmni.com to request a free risk assessment.

In this episode:

  • Why do security tools fail?
  • Who's at fault, the tool or the administrators who configured the tool?
  • Is it usually because the control is ineffective or was the control misconfigured / ignored?
  • Do InfoSec produts have an efficacy issue or an implementation issue?

View Details

All links and images for this episode can be found on CISO Series.

We talk a lot on this show about what makes cybersecurity such a hard job, yet there are so many people who are in it and love it. What draws people to this profession and why do they love it so much?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our guest David Cross (@MrDBCross), CISO, Oracle SaaS Cloud.

Thanks to our podcast sponsor, Orca Security

Orca Security is the pioneer of agentless cloud security that is trusted by hundreds of enterprises globally. With continuous first-to-market innovations and expertise, the Orca Platform ensures security teams quickly identify and remediate risks to keep their businesses secure. Connect your first account in minutes by visiting www.orca.security.

In this episode:

  • We talk a lot on this show about what makes cybersecurity such a hard job, yet there are so many people who are in it and love it.
  • What draws people to this profession and why do they love it so much?
  • Do you love the ability to influence the organization and leadership?
  • Do you love making an impact by helping people and businesses with safer behaviors and activities?

View Details

All links and images for this episode can be found on CISO Series.

We expect our users to be perfect security responders even when the adversaries are doing everything in their power to trick them. These scams are designed to make humans respond to them. Why aren't we building our security programs to account for this exact behavior that is simply not going to go away?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Ken Athanasiou, CISO, VF Corporation.

Thanks to our podcast sponsor, Code42

In this episode:

  • Why do we expect our users to be perfect security responders even when the adversaries are doing everything in their power to trick them?
  • Aren’t these scams designed to make humans respond to them?
  • Why aren't we building our security programs to account for this exact behavior that is simply not going to go away?
  • Why do so many security practitioners treat our users as children to be managed instead of adults to be educated and assigned a level of accountability?

View Details

All links and images for this episode can be found on CISO Series.

How do you make the argument that your company needs a CISO, and that YOU should be that leader? What do you need to demonstrate to prove you can be that person?

Check out this post and this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our sponsored guest Radley Meyers (@radleymeyers), Partner, SPMB Executive Search.

Thanks to our podcast sponsor, SPMB

SPMB connects top executive talent to the world’s best and fastest growing innovators across the country. A key area we bring extensive knowledge and expertise to is our dedicated Security Practice, leading both functional searches (CISO and VP’s defining security strategy) and building out executive teams at top security software companies.

In this episode:

  • How do you make the argument that your company needs a CISO, and that YOU should be that leader?
  • What do you need to demonstrate to prove you can be that person?
  • Do you have a sound understanding of the WHY behind the organization's existence and how value is added or taken away?
  • How do you lay out a plan to win in whatever industry you are in because of security NOT despite it?

View Details

All links and images for this episode can be found on CISO Series.

How do you become a CISO? It doesn't follow a linear pattern as many other professions. There are many different paths and there are many different entry points.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Yabing Wang, CISO, Justworks.

Thanks to our podcast sponsor, SPMB

SPMB connects top executive talent to the world’s best and fastest growing innovators across the country. A key area we bring extensive knowledge and expertise to is our dedicated Security Practice, leading both functional searches (CISO and VP’s defining security strategy) and building out executive teams at top security software companies.

In this episode:

  • How do you become a CISO?
  • Why doesn't it follow a linear pattern as many other professions?
  • Why are there so many different paths and entry points?
  • Why is it valuable to know how others did it and how you can glean that knowledge and apply it to your situation?

View Details

All links and images for this episode can be found on CISO Series.

What would it take to build your entire security program on open source software, tools, and intelligence?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome guest DJ Schleen (@djschleen), distinguished security architect, Yahoo Paranoids.

Thanks to our podcast sponsor, SPMB

SPMB connects top executive talent to the world’s best and fastest growing innovators across the country. A key area we bring extensive knowledge and expertise to is our dedicated Security Practice, leading both functional searches (CISO and VP’s defining security strategy) and building out executive teams at top security software companies.

In this episode:

  • What would it take to build your entire security program on open source software, tools, and intelligence?
  • Is it possible/feasible/practical to run a security program entirely based upon free and open source software, open source tools, and open source intelligence?
  • Is it true that the more open source you use the more people you need?
  • Do commercial software systems, tools, and intelligence have value above what can be found in open source?

View Details

All links and images for this episode can be found on CISO Series.

Businesses grow based on trust, but they have to operate in a world of risk. Even cybersecurity operates this way, but when it comes to third party analysis, what if we leaned on trust more than trying to calculate risk?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and our guest co-host is Yaron Levi (@0xL3v1), CISO, Dolby. Yaron and I welcome Dan Walsh, CISO, VillageMD.

Thanks to our podcast sponsor, TrustCloud

TrustCloud is the all-in-one platform to accelerate sales and security reviews, automate compliance efforts, and map contractual liability across your business. Connect with us to learn how you can transform security from a cost center into a profit driver with TrustCloud’s programmatic risk and compliance verification tools.

In this episode:

  • When it comes to third party analysis, what if we leaned on trust more than trying to calculate risk?
  • Should we have a “glass half empty” or a “glass half full” attitude towards third party risk?
  • Wouldn't it be better to measure the level of how much we can TRUST the 3rd party?
  • Is it vitally important to assess how resilient the organization is to failure caused by each third party?

View Details

All links and images for this episode can be found on CISO Series

The cybersecurity sales process is so terribly inefficient. And everyone, the targets and cybersecurity leaders, are losing valuable time because of that inefficiency. Where can we start making improvements?

Check out this post for the discussion that's the basis for this podcast episode. This week's Defense in Depth is hosted by me, David Spark (@dspark), producer, CISO Series. Our guest co-host is John Overbaugh, CISO, ASG. John and I welcome our guest, Jerich Beason (@blanketsec), commercial CISO, Capital One.

Thanks to our podcast sponsor, Compyl

GRC solutions often cause process roadblocks within organizations. They are either antiquated and lack the functionality needed or so stripped down they can’t fix the problems you set to solve. That's why the team over at Compyl created the all-in-one security and compliance automation platform. Compyl quickly integrates with the tools you use, and automates 85% of the day-to-day tasks, all while providing complete transparency and comprehensive reporting along the way. Start your free trial with Compyl today and see all the efficiency gains you can expect from a leading solution. Learn about Compyl today at www.compyl.com/getstarted.

In this episode:

Why is the cybersecurity sales process so terribly inefficient? Where can we start making improvements? What could be done to improve the efficiency? What is the solution to removing wasted effort and time?

View Details

All links and images for this episode can be found on CISO Series.

When you think about building a plan (and budget!) for your security program, do you lead with risk, maturity, or something else?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Ngozi Eze, CISO, Levi Strauss.

Thanks to our podcast sponsor, runZero

runZero is the cyber asset management solution that helps you find and identify every managed and unmanaged asset connected to your network and in the cloud. Get the data and context needed to effectively manage and secure your environment. Try runZero for free at runzero.com.

In this episode:

  • When you think about building a plan (and budget!) for your security program, do you lead with risk, maturity, or something else?
  • What's the overall theme you lead with when you're building a security program?
  • Why is it an important question to answer before you build your program?
  • How greatly can it vary?

View Details

All links and images for this episode can be found on CISO Series

Why do strongly supported security frameworks have such severe limitations when building a security program?

Check out this post for the discussions that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our sponsored guest Stas Bojoukha, CEO, Compyl.

Thanks to our podcast sponsor, Compyl

GRC solutions often cause process roadblocks within organizations. They are either antiquated and lack the functionality needed or so stripped down they can’t fix the problems you set to solve. That's why the team over at Compyl created the all-in-one security and compliance automation platform. Compyl quickly integrates with the tools you use, and automates 85% of the day-to-day tasks, all while providing complete transparency and comprehensive reporting along the way. Start your free trial with Compyl today and see all the efficiency gains you can expect from a leading solution. Learn about Compyl today at www.compyl.com/getstarted.

In this episode:

  • Why do strongly supported security frameworks have such severe limitations when building a security program?
  • Is it because the product security landscape updates with such speed and ferocity that these frameworks can't keep up?
  • Are most regulatory and third-party compliance "programs" simply non-prescriptive?
  • Is the intention to achieve compliance with every single control?

View Details

All links and images for this episode can be found on CISO Series.

Why is there a cybersecurity skills gap? Practically everyone is looking to hire, and there are ton of people getting training and trying to get into the industry, but we still have this problem. Why?

Check out this post for the discussions that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome Edwin Covert (@ebcovert3), head of cyber risk engineering, Bowhead Specialty.

Thanks to our podcast sponsor, Orca Security

In this episode:

  • Why is there a cybersecurity skills gap?
  • Practically everyone is looking to hire, and there are tons of people getting training and trying to get into the industry, but we still have this problem. Why?
  • Is there a problem with the system of hiring junior people, training, and preventing burnout?
  • Is the problem gatekeepers who don't do anything to mentor or groom the next wave?

View Details

All links and images for this episode can be found on CISO Series.

Given that your company's security is dependent on the security of your partners and others, what can we do to get more organizations above the security poverty line?

Check out this post for the discussions that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our sponsored guest, Jason Kikta (@kikta), CISO, Automox.

Thanks to our podcast sponsor, Automox

Are you ready to ditch manual patching? With Automox, you can automatically patch your third-party applications, Windows, macOs, and Linux devices with one easy-to-use, cloud-native platform. Try for yourself with our free 15-day trial and have all your endpoints safe and secure in just 15 minutes.

In this episode:

  • Given that your company's security is dependent on the security of your partners and others, what can we do to get more organizations above the security poverty line?
  • How can we give them guidance towards working on priorities in cybersecurity?
  • How are the Vendors handling this?
  • Can we create an "Adopt a Highway" program for cybersecurity?

View Details

All links and images for this episode can be found on CISO Series.

"When the asset discovery market launched, every single company that offered a solution used the line, “You can’t protect what you don’t know.” Everyone agreed with that.

Problem is, “what you don’t know” has grown… a lot."

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our sponsored guest is Huxley Barbee (@huxley_barbee), security evangelist, runZero.

Thanks to our podcast sponsor, runZero

runZero is the cyber asset management solution that helps you find and identify every managed and unmanaged asset connected to your network and in the cloud. Get the data and context needed to effectively manage and secure your environment. Try runZero for free at runzero.com.

In this episode:

  • Everyone agrees that, “You can’t protect what you don’t know”, but what do you do when, “what you don’t know” has grown…a lot?
  • With all our efforts to know our assets, are we doing any better understanding?
  • How do we decide what we should really be measuring?
  • How do we determine what’s most important in terms of asset management?

View Details

All links and images for this episode can be found on CISO Series

A good high profile security threat seems like a good time to alert potential customers about how your product could help or even prevent a breach. Seems like a solid sales tactic for any industry that is not cybersecurity.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our guest Angela Williams, CISO, UL.

Thanks to our podcast sponsor, Automox

Are you ready to ditch manual patching? With Automox, you can automatically patch your third-party applications, Windows, macOs, and Linux devices with one easy-to-use, cloud-native platform. Try for yourself with our free 15-day trial and have all your endpoints safe and secure in just 15 minutes.

In this episode:

  • Is tying your product to a high profile event a good sales tactic for vendors?
  • How can vendors best help cybersecurity professionals during emergency situations?
  • Is there a correct way for vendors to capitalize on a high profile event?

View Details

All links and images for this episode can be found on CISO Series

Why do CISOs seem more stressed out than other C-level executives?

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our guest Jared Mendenhall, Head of information security, Impossible Foods.

Thanks to our podcast sponsor, Compyl

GRC solutions often cause process roadblocks within organizations. They are either antiquated and lack the functionality needed or so stripped down they can’t fix the problems you set to solve. That's why the team over at Compyl created the all-in-one security and compliance automation platform. Compyl quickly integrates with the tools you use, and automates 85% of the day-to-day tasks, all while providing complete transparency and comprehensive reporting along the way. Start your free trial with Compyl today and see all the efficiency gains you can expect from a leading solution. Learn about Compyl today at www.compyl.com/getstarted.

In this episode:

  • Do CISOs undergo more stress than other C-Suite jobs?
  • Why do CISOs seem more stressed out than other C-level executives?
  • Is it because the role is not fully formed and that CISOs don't get enough resources?
  • Do the blurred lines of the CISO job increase the stress? Even more so that the CEO?

View Details

All links and images for this episode can be found on CISO Series

How detailed do we get in our conversation with business leaders? Do we dumb it down? Or is that a recipe for trouble?

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our guest Lee Parrish (@leeparrish), CISO, Newell Brands.

Thanks to our podcast sponsor, Qualys

Qualys is a pioneer and leading provider of cloud-based security and compliance solutions.

In this episode:

  • How detailed do we get in our conversation with business leaders?
  • Do we dumb it down? Or is that a recipe for trouble?
  • To what level does the C-Suite need to be cyber savvy?
  • How essential is it for senior leaders to know more?

View Details

All links and images for this episode can be found on CISO Series

Why are there so many vCISOs who have never been a CISO? Isn't it difficult to advise on a role you've never done? Do organizations feel comfortable hiring an inexperienced vCISO as their CISO?

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our guest Steve Tran, CSO, DNC.

Thanks to our podcast sponsor, runZero

runZero is the cyber asset management solution that helps you find and identify every managed and unmanaged asset connected to your network and in the cloud. Get the data and context needed to effectively manage and secure your environment. Try runZero for free at runzero.com.

In this episode:

  • Why are there so many vCISOs who have never been a CISO?
  • Isn't it difficult to advise on a role you've never done?
  • Do organizations feel comfortable hiring an inexperienced vCISO as their CISO?
  • If the person has the requisite background, why does it matter what the title they had before is?

View Details

All links and images for this episode can be found on CISO Series

As an outside observer, how can you tell if a company is staying cyber healthy? While there is no financial statement equivalency to let you know the strength of a company's security profile, there are signals that'll give you a pretty good idea.

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our guest Matt Honea, CISO, SmartNews.

Thanks to our podcast sponsor, Automox

Are you ready to ditch manual patching? With Automox, you can automatically patch your third-party applications, Windows, macOs, and Linux devices with one easy-to-use, cloud-native platform. Try for yourself with our free 15-day trial and have all your endpoints safe and secure in just 15 minutes.

In this episode:

  • As an outside observer, how can you tell if a company is staying cyber healthy?
  • What are the signals to let you know the strength of a company's security profile?
  • How do we go about trying to determine a company's cyber health?
  • Why is it important to know about another company's cyber health?

View Details

All links and images for this episode can be found on CISO Series

The cyber attack surface just keeps growing to the point that it seems endless. Protecting it all is impossible. Is there anything that can be done to reduce that attack surface and limit your exposure?

Check out this post for the discussion that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our sponsored guest is Jonathan Trull (@jonathantrull), CISO, Qualys.

Thanks to our podcast sponsor, Qualys

Qualys is a pioneer and leading provider of cloud-based security and compliance solutions.

In this episode:

  • Is there anything that can be done to reduce that attack surface and limit your exposure?
  • Is attack surface reduction a new security development philosophy or is it just a rebranding of vulnerability management?
  • And what value does it have in comparison to other popular theories such as zero trust and defense in depth?
  • Is everything just another form of exposure management?

View Details

All links and images for this episode can be found on CISO Series

Those reports on security procedures for the business are falling short. No one is reading them. What good are security controls if your staff doesn't know about them or adhere to them? Is it time to hire a marketing manager for the security team?

Check out this post for the discussion that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Laura Deaner (@b3dwin), CISO, Northwestern Mutual.

Thanks to our podcast sponsor, IANS Research

CISOs, how does your compensation compare with your peers? Download IANS + Artico Search's 2022 CISO Compensation Benchmark Report. Find objective insights and comprehensive compensation data from over 500 CISOs across the U.S. and Canada.

In this episode:

  • What good are security controls if your staff doesn't know about them or adhere to them?
  • Is it time to hire a marketing manager for the security team?
  • Why does it make sense to think of who the stakeholder is and what’s happening in their world?
  • How to best build policies that don’t get ignored?

View Details

All links and images for this episode can be found on CISO Series

Cybersecurity budgets are increasing, by a lot. What's fueling the increase and where are those budgets being spent?

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our sponsored guest sponsored guest Nick Kakolowski, senior director of research at IANS Research.

Thanks to our podcast sponsor, IANS Research

CISOs, how does your compensation compare with your peers? Download IANS + Artico Search's 2022 CISO Compensation Benchmark Report. Find objective insights and comprehensive compensation data from over 500 CISOs across the U.S. and Canada.

In this episode:

  • What's fueling the increase in cybersecurity budgets and where are those budgets being spent?
  • Do we understand where the money is being spent? Is it on new hires? More tooling?
  • Does training new hires provide a good ROI for an increased budget?
  • Should we equate the success of a security program with the size of the budget? Or not?

View Details

All links and images for this episode can be found on CISO Series

Cybersecurity budgets are increasing, by a lot. What's fueling the increase and where are those budgets being spent?

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our sponsored guest sponsored guest Nick Kakolowski, senior director of research at IANS Research.

Thanks to our podcast sponsor, IANS Research

CISOs, how does your compensation compare with your peers? Download IANS + Artico Search's 2022 CISO Compensation Benchmark Report. Find objective insights and comprehensive compensation data from over 500 CISOs across the U.S. and Canada.

In this episode:

  • What's fueling the increase in cybersecurity budgets and where are those budgets being spent?
  • Do we understand where the money is being spent? Is it on new hires? More tooling?
  • Does training new hires provide a good ROI for an increased budget?
  • Should we equate the success of a security program with the size of the budget? Or not?

View Details

All links and images for this episode can be found on CISO Series

What's the difference between a head of security, a vp of security, and a CISO? Do job responsibilities change whether you're a security analyst or a threat engineer? Roles are confusing and so is the pay and responsibilities attached to them.

Check out this post and this post for the basis of today's discussion. this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Hadas Cassorla, CISO, M1. Our guest is Renee Guttman, former CISO of Coca-Cola, Time Warner, Campbells.

Thanks to our podcast sponsor, IANS Research

CISOs, how does your compensation compare with your peers? Download IANS + Artico Search's 2022 CISO Compensation Benchmark Report. Find objective insights and comprehensive compensation data from over 500 CISOs across the U.S. and Canada.

In this episode:

  • What's the difference between a head of security, a vp of security, and a CISO?
  • Do job responsibilities change whether you're a security analyst or a threat engineer?
  • Why are cyber security roles so confusing?
  • And why is there such a variance of pay and responsibilities attached to them?

View Details

All links and images for this episode can be found on CISO Series

What's the difference between a head of security, a vp of security, and a CISO? Do job responsibilities change whether you're a security analyst or a threat engineer? Roles are confusing and so is the pay and responsibilities attached to them.

Check out this post and this post for the basis of today's discussion. this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Hadas Cassorla, CISO, M1. Our guest is Renee Guttman, former CISO of Coca-Cola, Time Warner, Campbells.

Thanks to our podcast sponsor, IANS Research

CISOs, how does your compensation compare with your peers? Download IANS + Artico Search's 2022 CISO Compensation Benchmark Report. Find objective insights and comprehensive compensation data from over 500 CISOs across the U.S. and Canada.

In this episode:

  • What's the difference between a head of security, a vp of security, and a CISO?
  • Do job responsibilities change whether you're a security analyst or a threat engineer?
  • Why are cyber security roles so confusing?
  • And why is there such a variance of pay and responsibilities attached to them?

View Details

All links and images for this episode can be found on CISO Series

Instead of complaining about the security hiring process, walk a mile in a recruiter's shoes and have a little compassion to what they're going through, and how you might be able to help, at any level.

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap) with our guest Caleb Sima (@csima), CSO, Robinhood.

Thanks to our podcast sponsor, Safe Security

If your CFO or Board was to ask: ‘How much could we lose to a cyber attack?’ Would you know?

Introducing SAFE - the industry’s most complete Cyber Risk Quantification solution to help you answer those crucial questions in real-time:

  • Visualize and measure cyber risk across your entire estate
  • Discover your $ risk exposure per attack vector
  • Gain personalized, actionable insights to tackle your most critical risks
  • Communicate your real-time cyber risk posture to your Board

Learn more at www.safe.security

In this episode:

  • Instead of complaining about the security hiring process, CISOs should walk a mile in a recruiter's shoes and have a little compassion to what they're going through.
  • Have we thought about the process we’re creating for candidates?
  • Are we being responsible and thinking about the candidate's journey vs. being opportunistic?

View Details

All links and images for this episode can be found on CISO Series

Are security programs drifting from a prevention to a resilience strategy? If so, are you truly operating in a resilient environment? Or are you still acting in a prevention stance but you know you should be resilient?

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. We welcome our sponsored guest David Ratner (@davidhratner), CEO, HYAS.

Thanks to our podcast sponsor, HYAS

*"Better production environment security starts with visibility. After all, how can you protect your most valuable asset if you don’t know A: what’s expected and B: when something’s happening that isn’t expected?

This is why HYAS Confront monitors traffic to alert you to anomalies, letting you address risks, threats, and changes, while blocking infiltrations before they become successful attacks.

Don’t just react, take your security back with HYAS. Visit HYAS.com"*

In this episode:

  • Are security programs drifting from a prevention to a resilience strategy?
  • If so, are you truly operating in a resilient environment? Or are you still acting in a prevention stance but you know you should be resilient?
  • What does a resilience strategy look like?
  • How does your security stack change when you choose resilience?

View Details

All links and images for this episode can be found on CISO Series

How do you talk to non-technical business leaders about cybersecurity? It's a concern, it's a risk, they want to know so they can make logical business decisions. How do you help?

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Our guest is Sara Hall, deputy CISO, MassMutual.

Thanks to our podcast sponsor, HYAS

*"Better production environment security starts with visibility. After all, how can you protect your most valuable asset if you don’t know A: what’s expected and B: when something’s happening that isn’t expected?

This is why HYAS Confront monitors traffic to alert you to anomalies, letting you address risks, threats, and changes, while blocking infiltrations before they become successful attacks.

Don’t just react, take your security back with HYAS. Visit HYAS.com"*

In this episode:

  • How do you talk to non-technical business leaders about cybersecurity?
  • It's a concern, it's a risk, they want to know so they can make logical business decisions. How do you help?
  • Does storytelling and/or other strategies work?
  • How do you have a risk discussion while also avoiding FUD - fear, uncertainty, and doubt?

View Details

All links and images for this episode can be found on CISO Series

Why are cybersecurity professionals burning out? What's the dynamic of the job, the pressures being put on them, that causes the best to leave? And this industry can't afford to lose its best talent.

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and special guest co-host Shawn Bowen (@SMbowen), CISO, World Fuel Services. Our guest is Bozidar Spirovski (@spirovskib), CISO, Blue dot.

Thanks to our podcast sponsor, HYAS

Better production environment security starts with visibility. After all, how can you protect your most valuable asset if you don’t know A: what’s expected and B: when something’s happening that isn’t expected?

This is why HYAS Confront monitors traffic to alert you to anomalies, letting you address risks, threats, and changes, while blocking infiltrations before they become successful attacks.

Don’t just react, take your security back with HYAS. Visit HYAS.com

In this episode:

  • Why are cybersecurity professionals burning out?
  • What's the dynamic of the job, the pressures being put on them, that causes the best to leave?
  • Are certain areas of cyber are more prone to burnout than others?
  • Do we have a training and communication crisis in the field?

View Details

All links and images for this episode can be found on CISO Series

Why are cybersecurity professionals burning out? What's the dynamic of the job, the pressures being put on them, that causes the best to leave? And this industry can't afford to lose its best talent.

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and special guest co-host Shawn Bowen (@SMbowen), CISO, World Fuel Services. Our guest is Bozidar Spirovski (@spirovskib), CISO, Blue dot.

Thanks to our podcast sponsor, HYAS

Better production environment security starts with visibility. After all, how can you protect your most valuable asset if you don’t know A: what’s expected and B: when something’s happening that isn’t expected?

This is why HYAS Confront monitors traffic to alert you to anomalies, letting you address risks, threats, and changes, while blocking infiltrations before they become successful attacks.

Don’t just react, take your security back with HYAS. Visit HYAS.com

In this episode:

  • Why are cybersecurity professionals burning out?
  • What's the dynamic of the job, the pressures being put on them, that causes the best to leave?
  • Are certain areas of cyber are more prone to burnout than others?
  • Do we have a training and communication crisis in the field?

View Details

All links and images for this episode can be found on CISO Series

You're starting a security program from scratch and you're trying to figure out where to start, what to prioritize, and how to architect it so it grows naturally and not a series of random patches over time.

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO. Our guest is Mark Bruns, CISO, First Bank.

Thanks to our podcast sponsor, Keyavi

Myth: Data can’t protect itself. Fact: Now it does! You control where your data goes in the world, who can access it and when. On any device. Anytime. Anywhere. FOREVER. Learn more at Keyavi.com.

In this episode:

  • Have you ever had a purely greenfield situation?
  • When starting a security program from scratch, how do you figure out where to start and what to prioritize?
  • What are the top five actions if you were going to implement a brand new/greenfield security program?
  • How do you architect a security program so that it grows naturally and not a series of random patches over time?

View Details

All links and images for this episode can be found on CISO Series

You're starting a security program from scratch and you're trying to figure out where to start, what to prioritize, and how to architect it so it grows naturally and not a series of random patches over time.

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO. Our guest is Mark Bruns, CISO, First Bank.

Thanks to our podcast sponsor, Keyavi

Myth: Data can’t protect itself. Fact: Now it does! You control where your data goes in the world, who can access it and when. On any device. Anytime. Anywhere. FOREVER. Learn more at Keyavi.com.

In this episode:

  • Have you ever had a purely greenfield situation?
  • When starting a security program from scratch, how do you figure out where to start and what to prioritize?
  • What are the top five actions if you were going to implement a brand new/greenfield security program?
  • How do you architect a security program so that it grows naturally and not a series of random patches over time?

View Details

All links and images for this episode can be found on CISO Series

Files are still the core of how people do business. How are you dealing with the onslaught of files coming into your network? People are sharing files across a multitude of platforms, and many for which you may not even know about. What checks and balances do you put in place to make sure you've got file integrity no matter the source?

Check out this post for the discussion that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our sponsored guest is Aviv Grafi, founder and CTO, Votiro.

Thanks to our podcast sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com. That’s v-o-t-i-r-o.com

In this episode:

  • How are you dealing with the onslaught of files coming into your network?
  • What checks and balances do you put in place to make sure you've got file integrity no matter the source?
  • Who has the authority to decide whether a file should be protected or deleted?

View Details

All links and images for this episode can be found on CISO Series

Files are still the core of how people do business. How are you dealing with the onslaught of files coming into your network? People are sharing files across a multitude of platforms, and many for which you may not even know about. What checks and balances do you put in place to make sure you've got file integrity no matter the source?

Check out this post for the discussion that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our sponsored guest is Aviv Grafi, founder and CTO, Votiro.

Thanks to our podcast sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com. That’s v-o-t-i-r-o.com

In this episode:

  • How are you dealing with the onslaught of files coming into your network?
  • What checks and balances do you put in place to make sure you've got file integrity no matter the source?
  • Who has the authority to decide whether a file should be protected or deleted?

View Details

All links and images for this episode can be found on CISO Series

Hiring managers speak about looking for culture fit and diversity, but never at the same time. Can they coexist? Are they mutually exclusive?

Check out this post for the discussion that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Sherron Burgess, CISO, BCD Travel.

Thanks to our podcast sponsor, Votiro

Can you trust that the files entering your organization are free of hidden threats like malware & ransomware? With Votiro you can. Votiro removes evasive and unknown malware from files in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with email, cloud apps & storage, and content collaboration platforms like Microsoft 365 - wherever files need to flow. Learn more at Votiro.com.

In this episode:

  • Hiring managers speak about looking for culture fit and diversity, but never at the same time. Can they coexist? Are they mutually exclusive?
  • How can you learn and grow as a company if everyone fits into one box?
  • Is reaching diversity an overnight achievement, or a longer journey?

View Details

All links and images for this episode can be found on CISO Series

Hiring managers speak about looking for culture fit and diversity, but never at the same time. Can they coexist? Are they mutually exclusive?

Check out this post for the discussion that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Sherron Burgess, CISO, BCD Travel.

Thanks to our podcast sponsor, Votiro

Can you trust that the files entering your organization are free of hidden threats like malware & ransomware? With Votiro you can. Votiro removes evasive and unknown malware from files in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with email, cloud apps & storage, and content collaboration platforms like Microsoft 365 - wherever files need to flow. Learn more at Votiro.com.

In this episode:

  • Hiring managers speak about looking for culture fit and diversity, but never at the same time. Can they coexist? Are they mutually exclusive?
  • How can you learn and grow as a company if everyone fits into one box?
  • Is reaching diversity an overnight achievement, or a longer journey?

View Details

All links and images for this episode can be found on CISO Series

Cyber sales is hard. But don't let the difficulty of doing it get in way of your good judgement. So what is the right way to follow up with a CISO?

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our guest is Jack Kufahl, CISO, Michigan Medicine.

Thanks to our podcast sponsor, SolCyber

At SolCyber we're hell-bent on delivering Fortune 500 level cyber security for small and medium-sized enterprises. When you're being targeted by the same bad guys, nothing else will do. We bring to the table a curated stack of leading technologies and around-the-clock SOC support, all simply priced per user. Let us do the heavy lifting.

In this episode:

  • What is the right way to follow up with a CISO?
  • How to prevent the difficulty of sales from clouding your good judgement?
  • What are some ideas on how best to reach out to CISOs and other potential customers?

View Details

All links and images for this episode can be found on CISO Series

One day you want to be a CISO. What area of security you begin your studies? Or maybe you shouldn't be studying security.

Check out this post for the discussion that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Evelin Biro (@wolfsgame), CISO, Alliant Credit Union.

Thanks to our podcast sponsor, Qualys

Qualys is a pioneer and leading provider of cloud-based security and compliance solutions.

In this episode:

  • What path should I take if I want to be a CISO?
  • What security jobs/roles best prepare you to become a CISO?
  • In what ways does the CISO role require totally different skills than the technical roles?

View Details

All links and images for this episode can be found on CISO Series

What can we do to reduce the damage of a breach and the duration of detection and remediation?

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our sponsored guest is Dave Klein (@cybercaffeinate), director, cyber evangelist, Cymulate.

Thanks to our podcast sponsor, Cymulate

The Ultimate Guide to Security Posture Validation: Learn how to effectively measure and reduce risk through continuous validation of your enterprise’s security posture. Download the playbook here.

In this episode:

  • What can we do to reduce the damage of a breach and the duration of detection and remediation?
  • How do we determine what’s most important and how to best reduce risk?
  • How can teams best reduce the impact of the "boom" you feel during a breach?

View Details

All links and images for this episode can be found on CISO Series

Learning cyber is not a question for those who are just starting out. It's for everybody. Where and how do we learn at every stage of our professional careers?

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our guest is Jerich Beason, CISO, Commercial, Capital One.

Thanks to our podcast sponsor, SlashNext

SlashNext protects the modern workforce from phishing and human hacking across all digital channels. SlashNext Complete™ utilizes our patented AI SEER™ technology to detect zero-hour phishing threats by performing dynamic run-time analysis on billions of URLs a day through virtual browsers and machine learning. Take advantage of SlashNext's phishing defense services for email, browser, mobile, and API.

In this episode:

  • Where do we go to learn at every stage of our professional careers?
  • We discuss how the learning process never really stops, but is on-going with cyber professionals continuing to learn throughout their careers.
  • Why is the “know-it-all” leader a red flag to avoid?

View Details

All links and images for this episode can be found on CISO Series

You’re a CISO, vCISO, or MSSP rolling into a company that has yet to launch a cybersecurity department. How do you communicate about cyber with the IT department? They’re not completely new to cyber. What’s the approach to engagement that helps, but doesn’t insult? How do you offer practical cybersecurity advice?

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our sponsored guest is sponsored guest Scott McCrady (@scottsman3), CEO, SolCyber.

Thanks to our podcast sponsor, SolCyber

At SolCyber we're hell-bent on delivering Fortune 500 level cyber security for small and medium-sized enterprises. When you're being targeted by the same bad guys, nothing else will do. We bring to the table a curated stack of leading technologies and around-the-clock SOC support, all simply priced per user. Let us do the heavy lifting.

In this episode:

  • How do you communicate about cyber with the IT department?
  • What’s the approach to engagement that helps, but doesn’t insult?
  • How do you offer practical cybersecurity advice?

View Details

All links and images for this episode can be found on CISO Series

Cybersecurity boils down to securing your data or data protection. But that simple concept has turned into a monumental task that is only exacerbated every time we move our data to a new platform. How do we secure data today, to be ready for whatever comes next in computing?

Check out this post and this post for the discussion that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and guest co-host Gary Hayslip (@ghayslip), global CISO, SoftBank Investment Advisers. Our sponsored guest is Elliot Lewis (@ElliotDLewis), CEO, Keyavi.

Thanks to our podcast sponsor, Keyavi

Myth: Data can’t protect itself. Fact: Now it does! You control where your data goes in the world, who can access it and when. On any device. Anytime. Anywhere. FOREVER. Learn more at Keyavi.com.

In this episode:

  • How do we secure data today, to be ready for whatever comes next in computing?
  • How do we go about building a data transformation program that's platform agnostic?
  • Why has this simple concept turned into a monumental task?

View Details

All links and images for this episode can be found on CISO Series

Is attack surface profiling the same as a pen test? If it isn't what unique insight can attack surface profiling deliver?

Check out this post for the discussion that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Nick Shevelyov, former CSO, Silicon Valley Bank.

Thanks to our podcast sponsor, Keyavi

Myth: Data can’t protect itself. Fact: Now it does! You control where your data goes in the world, who can access it and when. On any device. Anytime. Anywhere. FOREVER. Learn more at Keyavi.com.

In this episode:

  • Is attack surface profiling the same as a pen test?
  • What unique insight can attack surface profiling deliver?
  • Is “Attack Surface Profiling” more like a natural evolution from traditional vulnerability management?

View Details

All links and images for this episode can be found on CISO Series

What’s your best indicator that your security program is actually improving? And besides you and your team, is anyone impressed?

Check out this post for the discussion that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Simon Goldsmith (@cybergoldsmith), director of information security, OVO Energy.

Thanks to our podcast sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

In this episode:

  • What's the best indicator that your security program is actually improving?
  • Does anyone care that you're actually improving your security posture?
  • What should we be measuring to prove a security program is working and getting better?

View Details

All links and images for this episode can be found on CISO Series

Interviewing for leadership positions in cybersecurity is difficult for everyone involved. There are far too many egos and many gatekeepers. What can be done to improve recruiting of CISOs?

Check out this post and this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn with our guest Ty Sbano (@tysbano), CISO, Vercel.

Thanks to our podcast sponsor, Thinkst

Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this.
Deploy Canaries in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With 0 admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.

In this episode:

  • What can be done to improve CISO recruiting?
  • Is there a disconnect between HR and what the company actually needs regarding a position?
  • How long should the interview process take?

View Details

All links and images for this episode can be found on CISO Series

How are nefarious actors using our own data (and metadata) against us? And given that, in what way have we lost our way protecting data that needs to be course corrected?

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our sponsored guest is John Ayers (@cyberjohn1747), vp of advanced detection and response office of the CTO, Optiv.

Thanks to our podcast sponsor, Optiv

*The modern enterprise needs a solution as unique as its business.

Optiv’s Advanced Detection and Response (ADR) works with your organization to comb through the D&R clutter and find the ideal security solutions for your business. ADR delivers tailored detection and response backed by technology, real-time intel and deep expertise applied at touch. Bottom line: ADR finds and neutralizes threats fast, so you can focus on what matters.*

In this episode:

  • How are nefarious actors using our own data (and metadata) against us?
  • In what way have we lost our way protecting data that needs to be corrected?
  • We examine how our interconnectedness is both a blessing and a curse.
  • Is there already far too much sensitive data in essentially open source intelligence?

View Details

All links and images for this episode can be found on CISO Series

Is it possible to position your security team as a profit center instead of the traditional cost center reporting to the CIO?

Check out this post for the discussion that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Michael Weiss, CISO, Human Interest.

Thanks to our podcast sponsor, Optiv

*The modern enterprise needs a solution as unique as its business.

Optiv’s Advanced Detection and Response (ADR) works with your organization to comb through the D&R clutter and find the ideal security solutions for your business. ADR delivers tailored detection and response backed by technology, real-time intel and deep expertise applied at touch. Bottom line: ADR finds and neutralizes threats fast, so you can focus on what matters.*

In this episode:

  • Is it possible to position your security team as a profit center instead of the traditional cost center reporting to the CIO?
  • Is security still primarily an efficiency conversation or has effectiveness now changed the dialogue on how success is measured?
  • How to go about measuring the value cybersecurity provides the enterprise.
  • We examine the problems that can arise when security is treated as a profit center.

View Details

All links and images for this episode can be found on CISO Series

For years we've been referring to malware protection as a cat and mouse game. The crooks come up with a new malware attack, and then the good guys figure out a way to stop it. And that keeps cycling over and over again. So where are we today with malware protection and is there any way to get ahead of the cycle?

Check out this post and this post for the discussion that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our sponsored guest is Aviv Grafi (@avivgrafi), CTO and founder, Votiro.

Thanks to our podcast sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

In this episode:

  • How can we take proactive approaches that are capable of stopping attacks, not just detecting them?
  • What do you think we’re doing really well in terms of malware, and where could we do a lot better?
  • We examine the need for organizations to upgrade their defenses.
  • Has ransomware made a massive target out of every organization?

View Details

All links and images for this episode can be found on CISO Series

We all know and have experienced bad security awareness training. People can learn, and should learn about being cyber aware. How do you build a security awareness training program that sticks?

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn with our guest Lisa Kubicki (@lmk2), trust and security, training and awareness director, DocuSign.

Thanks to our podcast sponsor, Drata

Save 200+ hours with Drata's automated continuous compliance solution for SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, & CCPA. Drata connects to your techstack with 75+ integrations, including AWS, GitHub, GCP, & more to automate the compliance process. Kickstart your compliance journey by requesting a demo and get 10% off

In this episode:

  • We ask, “How do you build a security awareness training program that sticks?”
  • How do you develop a program that resonates with staff and actually improves security outcomes?
  • We get tips from the community on how they built a security awareness training program.
  • We examine what a successful engagement would look like.

View Details

All links and images for this episode can be found on CISO Series

You want to bring on entry level personal, But green employees, who are not well versed in security, IT, or your data introduce risk once they have access to it. What are ways to bring these people on while also managing risk?

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our guest is Rich Lindberg, CISO, JAMS.

Thanks to our podcast sponsor, SolCyber

At SolCyber we're hell-bent on delivering Fortune 500 level cyber security for small and medium-sized enterprises. When you're being targeted by the same bad guys, nothing else will do. We bring to the table a curated stack of leading technologies and around-the-clock SOC support, all simply priced per user. Let us do the heavy lifting.

In this episode:

  • We ask, “What are ways to bring entry-level people onboard the company while also managing risk?”
  • How does education stack up against on-the-job experience?
  • Are there advantages to hiring an inexperienced greenthumb versus experienced only new hires?

View Details

All links and images for this episode can be found on CISO Series Zero trust is a hollow buzzword. In any form of security, there exist critical points where we have to trust. What we need is a move away from implicit trust to explicit trust, or identity that can be verified.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our guest is Yaron Levi (@0xL3v1), CISO, Dolby.

Thanks to our podcast sponsor, Optiv

Need a guide on your Zero Trust journey? Jerry Chapman, Engineering Fellow at Optiv and author of "Zero Trust Security: An Enterprise Guide" shares the following takeaways:
- The key elements of Zero Trust
- How to visualize your Zero Trust journey and place it in the proper context
- Integrated technologies to drive adaptive processes and a mature security model
Learn more at www.optiv.com/zerotrust.

In this episode:

  • We ask cyber professionals, where is the ‘trust’ in zero-trust?
  • What and who should we be trusting?
  • How should we refer to zero trust since you can't run any kind of operation where you trust no one and nothing?

View Details

All links and images for this episode can be found on CISO Series

Cyber professionals, who is responsible on your team for investigating new solutions?

Check out this post and this post for the discussion that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Nick Ryan, director of enterprise technology security and risk, Baker Tilly.

Thanks to our podcast sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

In this episode:

  • We ask cyber professionals, who is responsible on their team for investigating new solutions? If it's a collaborative effort, how is that handled?
  • What are CISOs looking for in a solution?
  • And we discuss using existing solutions before purchasing and implementing more solutions.

View Details

All links and images for this episode can be found on CISO Series

In the cyber industry we pat each other on the back and give each other awards, all while the statistics for breaches appear to be worsening, Are we celebrating growing failure? Does the cyber industry suck?

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our guest is Fredrick Lee (AKA "Flee") (@fredrickl), Flee, CSO, Gusto.

Thanks to our podcast sponsor, Cymulate

The Ultimate Guide to Security Posture Validation: Learn how to effectively measure and reduce risk through continuous validation of your enterprise’s security posture. Download the playbook here.

In this episode:

  • We ask if our very own industry, ourselves, are the ones to blame for our constant woes?
  • Where do we stand in accepting fault and responsibility for the industry's continued problems?
  • Are the companies to blame for not taking IT seriously within their organizations?
  • Are industry awards just fluff for patting each other on the back?

View Details

All links and images for this episode can be found on CISO Series

For some, the definition of zero trust has expanded from how we grant access to networks, applications, and data to how we trust individuals in the real world. Are we taking zero trust too far?

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our guest is Thomas Doughty, CISO, Prudential Financial.

Thanks to our podcast sponsor, Netfoundry

NetFoundry, built on OpenZiti, is the only solution purpose-built to connect massively distributed apps, edges, clouds and devices in minutes, ensuring zero trust of the internet, local and OS host network and delivered as SaaS. Isolating the app to make network security irrelevant and remove the pain of public DNS, VPNs, bastions, as well as complex firewall rules.

In this episode:

  • We ask if we’re taking the concept of zero-trust too far.
  • We try to distinguish between where do we have to trust and where do we have to implement zero trust principles?
  • Differentiating between humans and machines when it comes to trust.
  • And is zero trust supposed to be a silver bullet or a cure-all?

View Details

All links and images for this episode can be found on CISO Series

Developers and security professionals have been heavily sold on the concept of "shift left" or deal with security issues early in development rather bolting it on at the end. It all made logical sense, but now we've been doing it for a few years and has shift-left actually reduced application security concerns?

Check out this post, this post, and this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our sponsored guest is Mike Gorman (@gormamic), head of security and compliance, NetFoundry.

Thanks to our podcast sponsor, Netfoundry

NetFoundry, built on OpenZiti, is the only solution purpose-built to connect massively distributed apps, edges, clouds and devices in minutes, ensuring zero trust of the internet, local and OS host network and delivered as SaaS. Isolating the app to make network security irrelevant and remove the pain of public DNS, VPNs, bastions, as well as complex firewall rules.

In this episode:

  • We look at dealing with security issues early in development rather than bolting it on at the end.
  • We ask whether or not application developers and security professionals are actually reducing security issues with "shift left” framework.
  • And do they actually reduce or even eliminate the need for other security controls?

View Details

All links and images for this episode can be found on CISO Series

Do we have a Monitgue/Capulet rivalry between technical and compliance professionals? Why is this happening, and what can be done to improve it? Does it need to be improved?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Linda White, director of InfoSec, Axiom Medical.

Thanks to our podcast sponsor, Netfoundry

NetFoundry, built on OpenZiti, is the only solution purpose-built to connect massively distributed apps, edges, clouds and devices in minutes, ensuring zero trust of the internet, local and OS host network and delivered as SaaS. Isolating the app to make network security irrelevant and remove the pain of public DNS, VPNs, bastions, as well as complex firewall rules.

In this episode:

  • We look at the Monitgue/Capulet rivalry between technical and compliance professionals.
  • Is there a solution to this never-ending feud?
  • And what can be done to improve relations?

View Details

All links and images for this episode can be found on CISO Series

Why do we end up with so many bad security products? Who is to blame and how can we fight back an ecosystem that may be fostering subpar products?

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our sponsored guest is Haroon Meer (@HaroonMeer), founder and researcher, Thinkst Canary.

Thanks to our podcast sponsor, Thinkst Canary

Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this.
Deploy Canaries in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With 0 admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.

In this episode:

  • Is the cybersecurity ecosystem giving a rise to subpar products?
  • Why are so many security products implemented poorly
  • How important is vendor feedback?

View Details

All links and images for this episode can be found on CISO Series

What are you doing to prepare for the next cyber disaster? You must train for it, because when it happens, and it will happen, everyone should know what they need to do.

Check out this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our guest is Roland Cloutier (@CSORoland), CISO, TikTok.

Thanks to our podcast sponsor, Keyavi

Data that protects itself? Now it does! We made data so smart it can think for itself. Secure itself. Stay continually aware of its surroundings. Control where, when and who is allowed access. And automatically report back to its owner. This changes the entire cybersecurity paradigm. Learn how.

In this episode:

  • What is the importance of cyber crisis management and training?
  • What are the best ways to prepare for a cyber disaster?
  • How to build exercises and training into a successful cybersecurity culture?

View Details

All links and images for this episode can be found on CISO Series

What if you didn't spend all your time patching vulnerabilities but instead created a security policy that prevented known vulnerabilities from being exploited. How doable is this solution of virtual patching?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Ody Lupescu, CISO, Ethos Life.

Thanks to our podcast sponsor, Araali Networks

Managing vulnerabilities at the speed and scale of the cloud is challenging, especially when the implications of a single mistake gives attackers an asymmetric advantage over defenders. Araali allows your security teams to resilient patch and monitor the most valuable apps and services so they cannot be exploited even if they are vulnerable. To learn more, visit araali.

In this episode:

  • What is virtual patching really? Is it a misnomer?
  • What gets missed when it comes to virtual patching?
  • Looking at a comprehensive approach to virtual patching.

View Details

All links and images for this episode can be found on CISO Series

A 500+ person company doesn't have a security department. They need one and they need to convince the CEO they need one. How do you build a cybersecurity team and program from scratch?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our guest is Rishi Tripathi (@ris12hi), CISO, Mount Sinai Health System.

Thanks to our podcast sponsor, Tines

Tines was founded by experienced security practitioners who cared about their teams. When they couldn’t find an automation platform that delivered, they founded a company and built their own. A few years later, customers like Coinbase, McKesson, and GitLab run their most important security workflows on Tines – everything from phishing response to employee onboarding. To learn more, visit tines.com.

In this episode:

  • How to go about measuring risk?
  • Leveraging compliance to get the point across.
  • What needs to be considered to make a program uniquely geared to your company's needs?

View Details

All links and images for this episode can be found on CISO Series

"If you want to catch a cybercrook, you need to think like one." But how do you actually go about thinking like a cybercriminal? What's the actual process?

Check out this post and this post for the discussions that are the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn.

Our guest is Brian Brushwood (@shwood), creator of Scam School and World's Greatest Con. Plus he's launched multiple channels with millions of subscribers and multiple number one comedy albums. Plus, he's a touring magician. He's our first non-cyber professional guest, but he is so perfect for this episode.

Thanks to our sponsor, Varonis

On average, an employee can access 17 million files on day one. Varonis will show you where critical data is vulnerable, detect anomalies, and automatically right-size privileges to get you to “Zero Trust.” Their data security platform can test your ransomware readiness and show you where you stack up. Learn more at www.varonis.com/cisoseries.

In this episode:

  • How much does actively thinking like a crook help build your cyber defenses?
  • How do you actually go about thinking like a cybercriminal
  • How do you break down their process?

View Details

All links and images for this episode can be found on CISO Series

Could you build a data-first security program? What would you do if you focused your security program on just the asset?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our sponsored guest is Brian Vecci (@brianthevecci), field CTO, Varonis.

Thanks to our sponsor, Varonis

On average, an employee can access 17 million files on day one. Varonis will show you where critical data is vulnerable, detect anomalies, and automatically right-size privileges to get you to “Zero Trust.” Their data security platform can test your ransomware readiness and show you where you stack up. Learn more at www.varonis.com/cisoseries.

In this episode:

  • Do I know where my sensitive data lives? How can I tell?
  • Why do all the tools that try to classify data fail miserably?
  • How much should we teach the data owners about risks in collecting and storing the information?

View Details

All links and images for this episode can be found on CISO Series

Offensive security or "hacking back" has always been seen as either unethical or illegal. But now, we're seeing a resurgence in offensive security solutions. Are we redefining the term, or are companies now "hacking back?"

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Eric Hussey, CISO, Aptiv.

Thanks to our podcast sponsor, Varonis

On average, an employee can access 17 million files on day one. Varonis will show you where critical data is vulnerable, detect anomalies, and automatically right-size privileges to get you to “Zero Trust.” Their data security platform can test your ransomware readiness and show you where you stack up. Learn more at www.varonis.com/cisoseries.

In this episode:

  • Has the definition of offensive security changed?
  • Can we truly fight back without legal repercussions?
  • How does it apply when hackers hide behind proxies?
  • Is hacking back even worth it?

View Details

All links and images for this episode can be found on CISO Series

A security professional announces a new position as CISO. As a vendor you see this as good timing to try a cold outreach to sell your product. Why do so many vendors think this is a good tactic, when in reality it’s exactly what you should not do?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our guest is Yaron Levi (@0xL3v1), CISO, Dolby.

In this episode:

  • Is the pouncing on new CISOs actually a successful sales technique?
  • Should vendors refine their relationship, and focus on "pull" rather than "push"?
  • What about focusing on content marketing and thought leadership?
  • Should vendors shift from "marketplace" to "metricplace?"

View Details

All links and images for this episode can be found on CISO Series

How do you begin building a cyber security culture for the whole company? And more importantly, how do you maintain that?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our guest is Mike Hanley (@_mph4), CSO, GitHub.

Thanks to our podcast sponsor, Anjuna

Anjuna Confidential Cloud software effortlessly enables enterprises to safely run even their most sensitive workloads in the public cloud. Unlike complex perimeter security solutions easily breached by insiders and malicious code, Anjuna leverages the strongest secure computing technologies available to make the public cloud the most secure computing resource anywhere.

In this episode:

  • When building a cybersecurity culture, where is the most important place to start?
  • How can we avoid it just becoming "lip service"?
  • How can we blend cybersecurity culture into the main corporate culture?

View Details

All links and images for this episode can be found on CISO Series

You're a security vendor and you've got a short briefing with a security analyst from a research firm. What do you want to get across to them, and what do you want to hear back from them?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our guest is Ed Amoroso (@hashtag_cyber), founder and CEO, Tag Cyber.

Huge thanks to our sponsor, Cymulate

The Ultimate Guide to Security Posture Validation: Learn how to effectively measure and reduce risk through continuous validation of your enterprise’s security posture. Download the playbook here.

In this episode:

  • What are the right questions to ask?
  • How can we better understand each other?
  • What to NOT do in an analyst conversation

View Details

All links and images for this episode can be found on CISO Series

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our sponsored guest is Michael Johnson, CISO, Novi (the financial arm of Meta, formerly Facebook)

Thanks to our podcast sponsor, Anjuna

Anjuna Confidential Cloud software effortlessly enables enterprises to safely run even their most sensitive workloads in the public cloud. Unlike complex perimeter security solutions easily breached by insiders and malicious code, Anjuna leverages the strongest secure computing technologies available to make the public cloud the most secure computing resource anywhere.

In this episode:

  • Which is safer for sensitive data: public cloud or on-prem?
  • Is it the technology, the people or the process that makes the difference?
  • Who is most affected by the public/on-prem decision?
  • Where does technical debt fit into this?

View Details

All links and images for this episode can be found on CISO Series

Security professionals are drowning in activities. Not all of them can be valuable. What should security professionals stop doing be to get back some time?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Jim Rutt, CISO, Dana Foundation.

Thanks to our podcast sponsor, Thinkst

Most companies discover they’ve been breached way too late. Thinkst Canary fixes this: just 3 minutes of setup; no ongoing overhead; nearly 0 false positives, and you can detect attackers long before they dig in. Check out why our Hardware, VM and Cloud-based Canaries are deployed and loved on all 7 continents.

In this episode:

  • What tool or process should we stop doing to stop wasting time?
  • Are "third-party risk reviews" useful at all?
  • Can we smooth out the sales cycle?
  • Are users to blame, or are they the victims?

View Details

How seamless are Distributed Denial of Service or DDoS solutions today? If you get a denial of service attack, how quickly can these solutions snap into action with no manual response by the user?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our guest is Alastair Cooke (@demitasenz), analyst, GigaOm.

Huge thanks to our podcast sponsor, MazeBolt

In this episode:

  • Where should a DDoS solution reside?
  • What vital elements should go into a DDoS solution?
  • Do we need more automation and intelligence in these solutions?
  • How involved should the customer be with their DDoS solution?

View Details

All links and images for this episode can be found on CISO Series

Knowing is only one-third the battle. Another third is responding. And the last third is responding quickly. It’s not enough to just have the first two thirds. We need to be faster, but how?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Jason Elrod (@jasonelrod), CISO, MultiCare Health System.

Thanks to our podcast sponsor, Eclypsium

Eclypsium is the enterprise firmware security company. Our comprehensive, cloud-based platform identifies, verifies, and fortifies firmware and hardware in laptops, servers, network gear and devices. The Eclypsium platform secures against persistent and stealthy firmware attacks, provides continuous device integrity, delivers firmware patching at scale, and prevents ransomware and malicious implants.

In this episode:

  • What can we do as a pragmatic first step to make our cybersecurity teams quicker and more responsive?
  • Would continuous authorization and real time emergency messaging help?
  • Should we improve test automation?
  • What about people - better teaching & work conditions?

View Details

All links and images for this episode can be found on CISO Series

Automation was supposed to make cybersecurity professionals’ lives simpler. And it was supposed to solve the talent shortage. Has any of that actually happened?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our guest is Brian Lozada (@brianl1775), CISO, HBOMax.

Thanks to our podcast sponsor, deepwatch

Increasing ransomware attacks and their evolving sophistication have been putting more pressure on security teams than ever before. Luckily, managed detection and response (or MDR) has emerged as a critical component for improving security operations, reducing ransomware risk, and minimizing the overall impact an attack can have. Visit deepwatch.com to see how we help to prevent breaches for our customers, by working together.

In this episode:

  • Should we be disappointed with what automation has actually delivered?
  • Is it a tools vs people thing?
  • Should we be better at assessing the impact of automation?
  • Should we change the way we hire to help with automation?

View Details

All links and images for this episode can be found on CISO Series

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap), CISO, LinkedIn. Our sponsored guest is Josh Yavor (@schwascore), CISO, Tessian.

Thanks to our podcast sponsor, Tessian

95% of breaches are caused by human error.
But you can prevent them. Learn how Tessian can stop “OH SHT!” moments before they happen, why Tessian has been recognized by analysts like Gartner and Forrester, and which world-renowned companies trust the platform to protect their data.*

In this episode:

  • What do you do for the attacks your rule sets can't catch?
  • Would it help if we eliminated email systems as the standard b2b toolset for communications?
  • Are there any better ways to handle spearphishing?
  • Are you ready to add BCC - Business communications compromise to your threat list?

View Details

All links and images for this episode can be found on CISO Series

Why is cybersecurity becoming so complex? What is one thing we can do, even if it's small, to head us off in the right direction of simplicity?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Leda Muller, CISO at Stanford, Residential and Dining Enterprises.

Thanks to our podcast sponsor, Eclypsium

Eclypsium is the enterprise firmware security company. Our comprehensive, cloud-based platform identifies, verifies, and fortifies firmware and hardware in laptops, servers, network gear and devices. The Eclypsium platform secures against persistent and stealthy firmware attacks, provides continuous device integrity, delivers firmware patching at scale, and prevents ransomware and malicious implants.

In this episode:

  • Is cybersecurity becoming too complex?
  • Should we change the way we talk about security to management?
  • Maybe it's time to reframe the argument?

View Details

All links and images for this episode can be found on CISO Series

Security convergence is the melding of all security functions from physical to digital and personal to business. The concept has been around for 17 years yet organizations are still very slow to adopt. A company's overall digital convergence appears to be happening at a faster rate than security convergence.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Geoff Belknap (@geoffbelknap), CISO, LinkedIn, and our guest is Anne Marie Zettlemoyer (@solvingcyber), business security officer, vp, security engineering, MasterCard.

Thanks to our podcast sponsor, Tessian

95% of breaches are caused by human error.
But you can prevent them. Learn how Tessian can stop “OH SHT!” moments before they happen, why Tessian has been recognized by analysts like Gartner and Forrester, and which world-renowned companies trust the platform to protect their data.*

  • Why are we still holding back on security convergence?
  • Is it a matter of "if" or "when"?
  • What happens when physical and info security are run by different departments?
  • How can we measure the risks?

View Details

All links and images for this episode can be found on CISO Series

In most jobs there’s often a clear indicator if you’re doing a good job. In security, specifically security leadership, it’s not so easy to tell. “Nothing happening” is not an effective measurement. So how should security performance be graded?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Geoff Belknap (@geoffbelknap), CISO, LinkedIn, and our guest is Deneen DeFiore (@deneendefiore), CISO, United Airlines.

Thanks to our podcast sponsor, Tessian

In this episode:

  • How should security performance be graded?
  • Is "keeping it simple" the best option?
  • What's the best measurement option?

View Details

All links and images for this episode can be found on CISO Series

If we’re going to turn the tables against our adversaries, everything from our attitude to our action needs to change to a format where attacks and breaches are not normalized, and we know the what and how to respond to it quickly.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Geoff Belknap (@geoffbelknap), CISO, LinkedIn, and our sponsored guest Scott Scheferman (@transhackerism), principal strategist, Eclypsium.

Thanks to our podcast sponsor, Eclypsium

Eclypsium is the enterprise firmware security company. Our comprehensive, cloud-based platform identifies, verifies, and fortifies firmware and hardware in laptops, servers, network gear and devices. The Eclypsium platform secures against persistent and stealthy firmware attacks, provides continuous device integrity, delivers firmware patching at scale, and prevents ransomware and malicious implants.

  • Moving from a reactive to a proactive attitude
  • Accelerating teams' ability to respond before damage happens
  • Stopping marketing informing your strategy
  • Patching "fast enough to matter"

View Details

All links and images for this episode can be found on CISO Series

Is it too much experience? Is it that they're difficult to work with? Do they want too much money? Will they not be motivated? Are cyber professionals over the age of 40 being discriminated in hiring practices?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our guest is Ben Sapiro, head of technology risk and CISO at Canada Life.

Thanks to our podcast sponsor, Qualys

Qualys is a pioneer and leading provider of cloud-based security and compliance solutions.

In this episode:

  • Are cyber professionals over the age of 40 being discriminated in hiring practices?
  • Is "older experience" a threat to younger managers?
  • Do older professionals have too much attitude?
  • What other work options exist for the 40+ expert?

View Details

All links and images for this episode can be found on CISO Series

How do we turn the tide from reactive to proactive patch management? Does anyone feel good about where they are with their own patch management program? What would it take to get there?

Check out this post and this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our sponsored guest is Sumedh Thakar (@sumedhthakar), CEO, Qualys.

Thanks to our podcast sponsor, Qualys

Qualys is a pioneer and leading provider of cloud-based security and compliance solutions.

In this episode:

  • How do we turn the tide from reactive to proactive patch management?
  • Do cultural differences make a difference?
  • Do we need a new framework or template?

View Details

All links and images for this episode can be found on CISO Series

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Geoff Belknap (@geoffbelknap), CISO, LinkedIn, and our guest Tony Sager (@sagercyber), svp, and chief evangelist, Center for Internet Security.

Thanks to our podcast sponsor, Qualys

In this episode:

  • What role should HR play in the hiring process of cybersecurity candidates?
  • What happens when HR's algorithms don't see the right keywords?
  • What are some better ways to get noticed by a human decision maker?

View Details

All links and images for this episode can be found on CISO Series

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Geoff Belknap (@geoffbelknap), CISO, LinkedIn, and our guest Andy Ellis (@csoandy), operating partner, YL Ventures.

Thanks to our podcast sponsor, Varonis

What is your ransomware blast radius? The average user can access 17 million files. Varonis reduces your blast radius in days, not years. Combined with advanced detection that monitors every file touch, ransomware doesn’t stand a chance. Get a free risk assessment.

In this episode:

  • What are some "positive vendor engagement" characteristics?
  • What tips can we share with vendors who want to build a lasting good impression?
  • How can a vendor go about building trust?

View Details

All links and images for this episode can be found on CISO Series

When a senior person at your company asks you, "Are we secure?" how should you respond?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Steve Zalewski, and our guest Paul Truitt, principal US cyber practice leader, Mazars.

Thanks to our podcast sponsor, Varonis

Still in the news is REvil’s ransomware attack on Kaseya VSA servers. Varonis is here to help mitigate the blast radius of such attacks. Want a step-by-step guide on what you should be looking for? Learn more about how to prevent ransomware.

In this episode:

  • When a senior, non-technical person asks, "Are we secure?" how do you respond?"
  • What does this question say about an executive's engagement level?
  • Why are they asking this now?
  • How relevant/accurate is this question anyway?

View Details

What are the tell tale signs you've got ransomware before you receive the actual ransomware threat?

Check out this post and this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Geoff Belknap (@geoffbelknap), CISO, LinkedIn, and our sponsored guest Brian Vecci (@BrianTheVecci), field CTO, Varonis.

Thanks to our podcast sponsor, Varonis

What is your ransomware blast radius? The average user can access 17 million files. Varonis reduces your blast radius in days, not years. Combined with advanced detection that monitors every file touch, ransomware doesn’t stand a chance. Get a free risk assessment.

In this episode:

  • How to catch the ransomware threat earlier
  • The individual capabilities needed in a full anti-ransomware stack
  • Honeypots and anomalous behavior
  • Back to basics: look at how ransomware works

View Details

All links and images for this episode can be found on CISO Series

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Geoff Belknap (@geoffbelknap), CISO, LinkedIn, and our guest Robert Wood (@holycyberbatman), CISO at Centers for Medicare & Medicaid Services.

Thanks to our podcast sponsor, Living Security

Traditional approaches to security communication are limited to one-off training sessions that fail to take customers, regulators, and other external stakeholders into account and rarely affect long-term behavioral change. This report lays out a four-step plan that CISOs should follow to manage the human risk. It provides design principles for creating transformational security awareness initiatives which will win the hearts and minds of senior executives, employees, the technology organization, and customers.

In this episode:

  • Will there be a day that phishing can be solved by technology?
  • Does more training lower risk?
  • Is it enough just to protect "inside" the environment?
  • What can we do to change the culture?

View Details

All links and images for this episode can be found on CISO Series

SIEM tools that ingest and analyze data are ubiquitous in security operations centers. But just knowing what's happening in your environment is not enough. For competitive reasons, must SIEM tools expand and offer more automation, intelligence, and the ability to act on that intelligence?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Geoff Belknap (@geoffbelknap), CISO, LinkedIn, and our guest Chris Grundemann (@ChrisGrundemann), category lead, security, GigaOm.

Thanks to our podcast sponsor, Keyavi

Cyber criminals who attack healthcare systems know medical record information has tremendous value for stealing identities. If you infuse personally identifiable information with geographical awareness and intelligence, you dramatically reduce the risk of patient identity theft. Join a live demo session on www.keyavi.com/sessions to learn more.

In this episode:

  • Will products from these two categories just merge as one product?
  • Or will they NEED to merge?
  • Are there advantages for them to stay separate?
  • Where does “trust” fit into this merger?

View Details

All links and images for this episode can be found on CISO Series

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Steve Zalewski, and our guest Adam Keown, director, information security, Eastman.

Thanks to our podcast sponsor, VMware

In this episode:

  • What's more valuable to get hired: degrees or experience?
  • What's better: narrow focus or broad skill range?
  • What's more attractive: knowledge or drive?
  • What's the deal: is there even such a thing as "entry level"?

View Details

All links and images for this episode can be found on CISO Series

What is the most critical step to preventing ransomware? Security professionals may be quick to judge users and say it's a lack of cyberawareness. Could it be something else?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Geoff Belknap (@geoffbelknap), CISO, LinkedIn, and our guest Rebecca Harness (@rebeccaharness), CISO, St. Louis University.

Thanks to our podcast sponsor, VMware

In this episode:

  • What is the one critical step to preventing ransomware?
  • The importance of leadership and employee buy-in
  • How to make training and education actually work
  • Should backups be included on this list?
  • What about the supply chain?

View Details

All links and images for this episode can be found on CISO Series

For four years in a row, Verizon's DBIR, has touted compromised credentials as the top cause of data breaches. That means bad people are getting in yet appearing to be legitimate users. What are these malignant users doing inside our network? What are the techniques to both understand and allow for good yet thwart bad lateral movement?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Steve Zalewski, and our sponsored guest Sandy Wenzel (@malwaremama), cybersecurity transformation engineer, VMware.

Thanks to our podcast sponsor, VMware

In this episode:

  • Why are bad people getting inside our networks?
  • Can machine learning help find them?
  • How can we separate lateral movement from credential stuffing?
  • Would using threat modeling and going passwordless help?

View Details

All links and images for this episode can be found on CISO Series

You've just joined a company as CISO, what's the very first step you would take to improve the security posture of your new company?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Steve Zalewski, and our guest Olivia Rose, vp of IT and security, Amplitude.

Thanks to our podcast sponsor, Proofpoint

Sixty six percent of CISOs feel their organization is unprepared to handle a cyberattack and 58% consider human error to be their biggest cyber vulnerability. Proofpoint's 2021 Voice of the CISO report explores key challenges facing CISOs after an unprecedented twelve months. Get the report.

In this episode:

  • How can new CISOs fast-track their learning process to make better decisions sooner?
  • How much does the CISO need to know about the environment before they start pentesting?
  • Using a " Power Interest Matrix" to help manage the people who influence your work
  • Why aligning with HR is a key move

View Details

All links and images for this episode can be found on CISO Series

How is ransomware getting into your network? Is the path direct, like via email, or does it take a more circuitous route?

Check out this post and this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Steve Zalewski, and our sponsored guest Ryan Kalember (@rkalember), evp, cybersecurity strategy, Proofpoint.

Thanks to our podcast sponsor, Proofpoint

Sixty six percent of CISOs feel their organization is unprepared to handle a cyberattack and 58% consider human error to be their biggest cyber vulnerability. Proofpoint's 2021 Voice of the CISO report explores key challenges facing CISOs after an unprecedented twelve months. Get the report.

In this episode:

  • What role do email and phishing actually play?
  • Has working from home really increased the threat?
  • How dwell time has changed things
  • Getting up to speed on sufficient backups

View Details

All links and images for this episode can be found on CISO Series

Why should security professionals get certifications? Do they actually teach you what you need to know to solve cybersecurity challenges? OR do they act as gateways or approval checks to be admitted into the field of cybersecurity?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, guest co-host Will Gregorian (@willgregorian), head of IT and security, Rhino and our guest Shawn M. Bowen (@smbowen), CISO, World Fuel Services.

Thanks to our podcast sponsor, Palo Alto Networks

First, every company became a software company. Now, every company needs to be a cybersecurity company too. Prisma Cloud from Palo Alto Networks a single security platform that delivers comprehensive protection from code through app, so your company can keep doing what it's supposed to do. Learn more at paloaltonetworks.com/prisma/cloud.

In this episode:

  • Are certifications like the CISSP necessary?
  • Even if they are necessary to get hired, are they relevant?
  • Let's say something good about certs.
  • Who benefits most from certs? The candidate or the hiring manager?

View Details

All links and images for this episode can be found on CISO Series

How are you measuring your progress and success with cloud security? How much visibility into this are you providing to your engineering teams?

Check out this post and this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Geoff Belknap (@geoffbelknap), CISO, LinkedIn and our sponsored guest Matthew Chiodi (@mattchiodi), CSO, public cloud, Palo Alto Networks.

Thanks to our podcast sponsor, Palo Alto Networks

If you're doing cloud security right, no one knows if you've done anything. When you do it wrong, well, you end up on Cybersecurity Headlines. Prisma Cloud from Palo Alto Networks helps ensure your security stays in the quietly appreciated group. It's a single security platform that delivers comprehensive protection from code to cloud. Learn more at paloaltonetworks.com/prisma/cloud.

In this episode

  • What requirements need to be measured?
  • Measuring against compliance
  • Building a company-specific guardrails framework
  • Measuring team performance by number of opened and closed issues

View Details

All links and images for this episode can be found on CISO Series

What does a young person, eager to get into cybersecurity, have to show or prove to land their first help desk, tech support role?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Geoff Belknap (@geoffbelknap), CISO, LinkedIn and our guest Bryan Zimmer (@bryanzimmer), head of security, Humu.

Thanks to our podcast sponsor, Palo Alto Networks

In 1666, Sir Isaac Newton famously used a prism to disperse white light into colors. Today, cloud security professionals use Prisma Cloud from Palo Alto Networks to disperse full lifecycle security and full stack protection across their multi- and hybrid-cloud environments. We think Sir Isaac would approve. Learn more about Prisma Cloud paloaltonetworks.com/Prisma/cloud.

In this episode

  • Balancing out certifications and experience
  • If we train you, will you stay, or will you leave?
  • What's your compelling story that shows what you can do?
  • Researching the competition: what are other candidates doing?

View Details

All links and images for this episode can be found on CISO Series

What do we want the Board and C-Suite to know about cybersecurity? If you could teach them one thing about cybersecurity that would stick, what would that be?

Check out this post and this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Geoff Belknap (@geoffbelknap), CISO, LinkedIn and our guest Phil Huggins (@oracuk), CISO, NHS Test & Trace, Department of Health and Social Care.

Thanks to our podcast sponsor, Proofpoint

Sixty six percent of CISOs feel their organization is unprepared to handle a cyberattack and 58% consider human error to be their biggest cyber vulnerability. Proofpoint's 2021 Voice of the CISO report explores key challenges facing CISOs after an unprecedented twelve months. Get the report.

In this episode

  • What the Board needs to know to make the CISO’s job more effective
  • It’s not about the Board understanding cyber – but it is about mitigating risk
  • Security is a shared responsibility: Board & CISOs
  • Using other companies’ breaches as Board learning opportunities

View Details

All links and images for this episode can be found on CISO Series

The demand for CISOs is growing due to increased regulations and cyber threats. Yet, while the demand is there, the supply keeps rotating. Companies think the next CISO is going to fix the problems of the last one. Why is a CISO's tenure so short and why is the hiring process for CISOs so disjointed?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, Steve Zalewski, and Gary Hayslip (@ghayslip), CISO, Softbank Investment Advisers

Thanks to our podcast sponsor, RevCult

On average, 18 percent of all your Salesforce data fields are highly sensitive and 89 percent of users have access to that data. RevCult is the only solution that helps you understand the data you have in Salesforce, and if you’re protecting it. Get a free Salesforce Security Self-Assessment to understand your Salesforce security weaknesses.

In this episode:

  • Why a CISO's tenure is so short and why they leave
  • The value of keeping risk management in the CISO’s sights
  • The need to clarify the CISO role in the mind of the executive
  • The need to clarify the CISO role in the mind of the CISO

View Details

All links and images for this episode can be found on CISO Series

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, guest co-host Liam Connolly, CISO, Seek. and our guest Ben Sapiro (@ironfog), head of technology risk and CISO, Canada Life.

Thanks to our podcast sponsor, RevCult

On average, 18 percent of all your Salesforce data fields are highly sensitive and 89 percent of users have access to that data. RevCult is the only solution that helps you understand the data you have in Salesforce, and if you’re protecting it. Get a free Salesforce Security Self-Assessment to understand your Salesforce security weaknesses.

In this episode:

  • What actions can a manager take to retain staff?
  • What do team members/employees want?
  • How important is team chemistry?
  • Establishing a creative thinking culture

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-salesforce-security/

Thanks to our podcast sponsor, RevCult

On average, 18 percent of all your Salesforce data fields are highly sensitive and 89 percent of users have access to that data. RevCult is the only solution that helps you understand the data you have in Salesforce, and if you’re protecting it. Get afree Salesforce Security Self-Assessmentto understand your Salesforce security weaknesses.

In this episode:

  • Where is Salesforce delivering in security controls and where is it falling short?
  • Salesforce security is more than just a single topic
  • Working with 3rd party SalesForce apps

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-cloud-configuration-fails/

Why do we hear so many stories about incidents related to poor or misconfigured cloud services?

Check out this post and this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Geoff Belknap (@geoffbelknap), CISO, LinkedIn and our sponsored guest, Brendan O'Connor, CEO, AppOmni.

Thanks to our podcast sponsor, AppOmni

AppOmni is building the future of SaaS security. We empower our users to enforce security standards across their SaaS applications, and enable them to remediate in confidence knowing they’re fixing the most important SaaS security issues first. Contact us at www.appomni.com to find out who - and what - has access to your SaaS data.

In this episode:

  • Why configuration drift and 3rd party access are still significant issues
  • Are cloud providers to blame?
  • The dynamic nature of cloud over time – we can’t keep up!
  • Who is ultimately responsible?

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/starting-pay-for-cyber-staff/

What should an entry level cybersecurity person be paid? And what level of education and training should be expected of them?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, guest co-host Naomi Buckwalter (@ineedmorecyber), director of information security and IT at Beam Technologies, and our guest Dan Walsh (@danwalshciso), CISO, VillageMD.

Thanks to our podcast sponsor, AppOmni

AppOmni is building the future of SaaS security. We empower our users to enforce security standards across their SaaS applications, and enable them to remediate in confidence knowing they’re fixing the most important SaaS security issues first. Contact us at www.appomni.com to find out who - and what - has access to your SaaS data.

In this episode:

  • Discussing the $15/hour entry level position
  • Why are qualified people applying for low paying entry level jobs?
  • The classic: This entry level position needs prior experience
  • Assessing the value that interns can bring

View Details

All links and images for this episode can be found on CISO Series.

https://cisoseries.com/fear-of-automation/

Why are security professionals so darn afraid of automation? We continue to hold on to the idea that people have to be integral in the real-time decision process to protect ourselves from the technology we deploy to protect us.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, and Steve Zalewski, CISO, Levi Strauss, with our guest Edward Frye (@edwardfrye), CISO, Aryaka Networks and president of Silicon Valley chapter of ISSA.

AppOmni is building the future of SaaS security. We empower our users to enforce security standards across their SaaS applications, and enable them to remediate in confidence knowing they’re fixing the most important SaaS security issues first. Contact us at www.appomni.com to find out who - and what - has access to your SaaS data.

In this episode:

  • Is it a fear of heavy lifting or not knowing what to lift?
  • Is it a fear of change or a fear of cost?
  • Is it a fear of automating human judgment?

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-hiring-talent-with-no-security-experience/

Should you look for the ideal candidate that has all the security talent you want, or should you find the right person and train them with the security talent you want. And if the latter, what is the right person to work in security who doesn't have security experience?

Check out this post and this Twitter discussion for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host, Geoff Belknap (@geoffbelknap), CISO, LinkedIn, and our guest Dev Akhawe (@frgx), CISO, Figma.

Thanks to our podcast sponsor, Sonatype

With security concerns around software supply chains ushered to center stage in recent months, organizations around the world are turning to Sonatype as trusted advisors. The company’s Nexus platform offers the only full-spectrum control of the cloud-native software development lifecycle including third-party open source code, first-party source code, infrastructure as code, and containerized code.

  • Is there a cyber talent shortage?
  • If so, does the shortage come from the hiring side?
  • The dangers of leaving positions open too long
  • The dangers of focusing on checklists vs. candidate potential

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-security-hygiene-for-software-development/

How do we improve the quality of our software? In the rush to be competitive, security has often taken a back seat to be first to market. What's the formula for fast and secure applications?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host, Geoff Belknap (@geoffbelknap), CISO LinkedIn, and sponsored guest Wayne Jackson, CEO, Sonatype.

Thanks to our podcast sponsor, Sonatype

In this episode:

  • Are we working too fast and under too much pressure to be secure?
  • What types of scanning should we do, and how often?
  • What about open source/third party software in the pipeline?
  • What are the dangers inherent in purchasing "secure software"?

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-how-much-do-you-know-about-your-data/

Do cybersecurity professionals even know what they're protecting? How aware are they of the data, its content and its sensitivity? What happens to your security posture when you do understand the data you're protecting? What can you do that you weren't able to do before?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, and Steve Zalewski, CISO, Levi Strauss, with our sponsored guest, Aidan Simister (@aidansimister), CEO, Lepide.

Thanks to our podcast sponsor, Lepide

Ninety eight percent of all threats start with Active Directory and nearly always involve the compromise of data stored on enterprise data stores. Lepide’s unique combination of detailed auditing, anomaly detection, real time alerting, and real time data discovery and classification allows you to identify, prioritize and investigate threats – fast.

In this episode:

  • How much do you know about the data you are being asked to protect?
  • Equating the value of the data to be protected with the cost of protection
  • How to find out how data is being used
  • Moving beyond the bare minimum of protection

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-do-startups-need-a-ciso/

Startups are all about proving the value of their product and growth. At the beginning, all of their money is funneled into product and market development. When do they need a CISO, if at all?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, and guest co-host Jimmy Sanders (@jfireluv), head of cybersecurity for Netflix DVD and our guest is Bryan Zimmer (@bryanzimmer), head of security for Humu.

Thanks to our podcast sponsor, Lepide

Ninety eight percent of all threats start with Active Directory and nearly always involve the compromise of data stored on enterprise data stores. Lepide’s unique combination of detailed auditing, anomaly detection, real time alerting, and real time data discovery and classification allows you to identify, prioritize and investigate threats – fast.

In this episode:

  • Should a company get a CISO right away, or wait until the security program matures?
  • If they get a CISO should they go for "on-prem" or on-demand?
  • Or.... should they just go and seek CISO-level advice from the security community?

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-insider-risk/

By just doing their jobs, your employees are introducing risk to the business. They don't mean to be causing issues, but their simple actions and sometimes mistakes can cause great harm. Is it their fault, or is it security's fault for not creating the right systems?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host, Steve Zalewski, CISO, Levis, and our sponsored guest Mark Wojtasiak (@markwojtasiak), vp, portfolio strategy & product marketing, Code42 and author of Inside Jobs: Why Insider Risk is the Biggest Cyber Threat You Can't Ignore.

Thanks to our podcast sponsor, Code42

Redefine data security standards for the hybrid workforce. Check out Code42.

In this episode:

  • Distractions and fatigue causing split-second mistakes
  • The need for tailored education and training
  • Making it easier for people to make the right choice
  • Identify ways damage could happen, in order to mitigate

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-whats-the-obsession-with-zero-trust/

Why is everyone obsessed with Zero Trust? Is it just a marketing ploy that vendors are using to sell their products? Or, is it truly a methodology that provides better security, especially in today's environment.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host, Geoff Belknap (@geoffbelknap), CISO LinkedIn, Melody Hildebrandt (@mhil1), evp, product & engineering and CISO, Fox.

Thanks to our podcast sponsor, Code42

Redefine data security standards for the hybrid workforce. Check out Code42.

In this episode

Does Zero Trust obscure the core principles it's supposed to serve?

How does Zero Trust affect the assumptions around cybersecurity’s control and ownership of a network

What are the real Zero Trust best practices?

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-mentoring/

Companies want security people with experience and they want to grow cybersecurity leaders. It's often hard to find that experience, and while there are certification courses aplenty, courses in cybersecurity leadership are hard to find. One possible solution is mentoring, but that has its own hurdles.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, guest co-host, Geoff Belknap (@geoffbelknap), CISO LinkedIn, and our guest Sean Catlett, CSO, Slack.

In this episode

  • The mutual value of being a mentor
  • What obligations does a mentee have?
  • Mentorship: large-scale concepts or day-to-day or both?

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-securing-the-super-bowl-and-other-huge-events/

How do cybersecurity professionals secure a huge event like the Olympics, the Superbowl, or a city's New Year's Eve party? What are the unique considerations that come into play?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, guest co-host Geoff Belknap (@geoffbelknap), CISO, LinkedIn, and our guest Tomás Maldonado (@tomas_mald), CISO, NFL

Thanks to our podcast sponsor, Lepide

Ninety eight percent of all threats start with Active Directory and nearly always involve the compromise of data stored on enterprise data stores. Lepide’s unique combination of detailed auditing, anomaly detection, real time alerting, and real time data discovery and classification allows you to identify, prioritize and investigate threats - fast.

In this episode

  • Protecting large events starts long before, like years before
  • How threat actors targeting events differ from than those targeting companies
  • It's not just the target - there's also public safety
  • When it goes live, it GOES LIVE

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-cybersecurity-isnt-that-difficult/

What are you security people complaining about? As compared to 10, 15, 20 years ago, the technical aspects of cybersecurity are not that difficult. We've got the control frameworks, tools, and training that are predecessors didn't have.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, guest co-host Naomi Buckwalter (@ineedmorecyber), director of information security and IT at Beam Technologies, and our guest, John Overbaugh (@johnoverbaugh), vp, security, CareCentrix

Thanks to our podcast sponsor, Trend Micro as bold

Threat actors want what you’re storing in the cloud. Trend Micro’s Cloud One platform provides cloud security from a single console, keeping you at your most resilient. Let what happens in the cloud, stay in the cloud.

In this episode

  • What infosec was like "back in the day"
  • What's out of alignment: the technology or the culture?
  • Can we really stand on the shoulders of giants amid so much change?
  • Where is individual cyberhygiene in all of this?

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-cloud-security-myths/

The cloud is inherently insecure! The cloud will handle all your security needs. More data breaches happen in the cloud. These are just some of the many many myths of cloud security. Listen as we debunk as many as we possibly can.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, guest co-host Steve Zalewski, CISO, Levis, and our sponsored guest Mark Nunnikhoven (@markna), vp, cloud research, Trend Micro.

Thanks to our podcast sponsor, Trend Micro

Threat actors want what you’re storing in the cloud. Trend Micro’s Cloud One platform provides cloud security from a single console, keeping you at your most resilient. Let what happens in the cloud, stay in the cloud.

In this episode

  • How many cloud myths from years back still endure?
  • Is cloud less secure or more secure now?
  • Who has the responsibility for security?
  • Just because you're in the cloud, does that mean you're protected?

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-what-is-securitys-mission/

What's the mission of your security program? Is it to proactively SECURE THE COMPANY against a compromise of the CONFIDENTIALITY, INTEGRITY, and AVAILABILITY, OR, is it to PROTECT THE COMPANY BRAND by effectively PREVENTing, DETECTING and RESPONDING to cyber-threats? These are the two options for security's mission that we discuss on this week's show.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, guest co-host Steve Zalewski, Deputy CISO, Levis, and our guest, Johna Till Johnson (@JohnaTillJohnso), CEO, Nemertes Research.

Thanks to our podcast sponsor, Trend Micro

The conversation between you and your board of directors is not always a walk in the park. With more cloud projects coming your way, it’s time to change the conversation to speak their language and start paving the way for a secure future. For more, go to http://trendmicro.com/CISO

In this episode

  • Security mission option 1: protecting the company
  • Security mission option 2: protecting the brand & revenue stream
  • Does one lead to/support the other?
  • Does the degree of cloud presence make a difference?
  • How much of this is technical vs philosophical?

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-vendor-cisos/

It's hard to be a CISO. But, what's it like to be a CISO at a security vendor, doing the hard work while carrying the stigma of being a "vendor"?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, guest co-host Geoff Belknap (@geoffbelknap), CISO, LinkedIn, and our sponsored guest Allan Alford (@AllanAlfordinTX), CTO/CISO, TrustMAPP, and host of The Cyber Ranch Podcast.

Thanks to our podcast sponsor, TrustMAPP

Does your board want to see yet more heat maps? No, they do not. They want to see that security investments align with business goals, and that their costs are objectively justified. TrustMAPP’s data visualization helps you communicate with your board in a way they can understand – and approve.

In this episode

  • How to balance being an advocate, an evangelist and an operator
  • Are there really "stigmas" to being a security vendor?
  • What's unique to practicing security while being a security vendor?

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-how-much-log-data-do-you-need

You're a CISO struggling with an influx of log data into your SIEM. What's the data you want to keep, and for how long? You want insights, but you also want to keep costs down. Holding onto everything is going to cost a fortune.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Steve Zalewski, deputy CISO, Levis, and our guest Naomi Buckwalter (@ineedmorecyber), director of information security and IT at Beam Technologies .

Thanks to our podcast sponsor, TrustMAPP

Does your board want to see yet more heat maps? No, they do not. They want to see that security investments align with business goals, and that their costs are objectively justified. TrustMAPP’s data visualization helps you communicate with your board in a way they can understand – and approve.

In this episode

  • So, what is the sweet spot for retaining log files? 90 days? 1 year?
  • Should you categorize according to business criticality?
  • How do you separate the "junk" from the valuable data?

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-should-finance-or-legal-mentor-cyber

Cybersecurity leaders are constantly looking for ways to improve how they think about risk, and how they communicate risk. But they're not the only ones. Others have been managing risk long before CISOs existed. So, who could be the best mentor to help a CISO gain better insight into business risk and how to communicate about it: the chief financial officer, or the legal department's general counsel?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, guest co-host Geoff Belknap (@geoffbelknap), CISO, LinkedIn, and our guest, David Schellhase (@davidschellhase), general counsel, Slack.

Thanks to our podcast sponsor, TrustMAPP

TrustMAPP delivers Security Performance Management, giving CISOs a real-time view of the effectiveness of their security program. TrustMAPP tells you where you are, where you’re going, and what it will take to get there. TrustMAPP gives organizations the ability to manage security as a business, quantifying and prioritizing remediation actions and costs. To learn about the MAPP methodology, download the white paper at https://trustmapp.com/mapp-paper/

In this episode

  • Which executive could a CISO learn more about risk?
  • Determining ROI of finance, legal and other execs
  • Analyzing why its so important to establish the ideal mentorship relationship

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-data-destruction

How do you deal with data at end of life? Holding onto data too long can be very costly and increase risk. So how do you get rid of it... safely?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, guest co-host Shawn Bowen, CISO, Restaurant Brands International (RBI), and our sponsored guest, Frank Milia, partner, (@ITAssetRecvry), IT Asset Management Group.

Thanks to our podcast sponsor, IT Asset Management

Poorly managed IT asset disposal, lack of due diligence, and a disposal program without clearly defined responsible parties has now resulted in millions of dollars in regulatory penalties. Is it clear who is responsible for the performance of your data disposition practice? IT Asset Management Group’s free program guide includes tips for establishing stakeholders at your organization and expectations for all practitioners.
Download the program guide today at
itamg.com/CISO

In this episode

  • Is the risk of holding onto data greater than the value of keeping it?
  • Should client data be considered a "toxic byproduct"?
  • When disposing of client data, how much destruction is enough?
  • What legal and regulatory requirements should be considered before destroying data?

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-how-to-make-cybersecurity-more-efficient/

You're a new CISO told to hold headcount even and find the resources to do 20% more work. We're already maxed out. So how do we do more? Coming up next we're getting smart and more efficient with security.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, guest co-host Steve Zalewski, Deputy CISO, Levis, and our guest, Mike Morgan, (@theywerecones) head of information security, infrastructure director, Foster Farms

Thanks to our podcast sponsor, IT Asset Management Group

Poorly managed IT asset disposal, lack of due diligence, and a disposal program without clearly defined responsible parties has now resulted in millions of dollars in regulatory penalties. Is it clear who is responsible for the performance of your data disposition practice? IT Asset Management Group’s free program guide includes tips for establishing stakeholders at your organization and expectations for all practitioners.
Download the program guide today at
itamg.com/CISO

In this episode

  • Improving processes right from the beginning of the pipeline
  • Looking for waste - and knowing what "waste" is
  • Doing more with less means at some point, something important will break
  • Delegating and crossing over skills
  • Watching out for IT sprawl and "new fangled" solutions

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-does-a-ciso-need-tech-skills

Does a CISO need technical skills to be an effective cybersecurity leader? Many CISOs don't have them. Are they still effective and does it affect their ability to lead?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, and guest co-host Ben Sapiro, (@ironfog), CISO, Great-West LifeCo, and our guest, Zach Powers, CISO, Benchling.

Thanks to our episode sponsor, IT Asset Management Group

Poorly managed IT asset disposal, lack of due diligence, and a disposal program without clearly defined responsible parties has now resulted in millions of dollars in regulatory penalties. Is it clear who is responsible for the performance of your data disposition practice? IT Asset Management Group’s free program guide includes tips for establishing stakeholders at your organization and expectations for all practitioners. Download the program guide today at itamg.com/CISO.

In this episode

  • Why having the skills helps with realistic expectations
  • Being able to see through the nonsense
  • The value of staying passionate about the profession

View Details

All links and images for this episode can be found on CISO Series

https://cisoseries.com/defense-in-depth-how-do-you-know-if-youre-good-at-security/

What metrics or indicators signal to you that an organization is “good at security”?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, guest co-host Geoff Belknap (@geoffbelknap), CISO, LinkedIn, and our guest Justin Berman (@justinmberman), former CISO, Dropbox.

Thanks to our podcast sponsor, Imperva

Face it, your data is everywhere! Imperva Data Security unifies compliance, security and privacy needs for any data store while saving you time and money. No matter where data lives, get confidence about what is happening with data, where it’s stored and who’s accessing it. Start a free trial now.

In this episode

  • How do go about measuring risk
  • Assessing the ratio of critical/high severity issues to issues closed
  • The difference between a reactive or proactive threat management policy

View Details

All links and images for this episode can be found on CISO Series

You're a new CISO at a new org given a headcount of ten to build a cybersecurity team. What's your strategy to build that team?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, guest co-host Steve Zalewski, Deputy CISO, Levis, and our guest JJ Agha (@jaysquaredx2), CISO, Compass.

Thanks to our podcast sponsor, Imperva

Face it, your data is everywhere! Imperva Data Security unifies compliance, security and privacy needs for any data store while saving you time and money. No matter where data lives, get confidence about what is happening with data, where it’s stored and who’s accessing it. Start a free trial now.

In this episode * The importance of assessments and gap analyses * Why you need to leveraging your network * Educating and empowering teams * Introspection and self-awareness as a leader

View Details

All links and images for this episode can be found on CISO Series

(https://cisoseries.com/defense-in-depth-are-our-data-protection-strategies-evolving/)

As we're evolving from putting data on premises to the cloud, are our data protection strategies evolving as well? There are issues of securing data, knowing where it travels, and privacy implications of data. How are we handling all of that?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and our sponsored guest, Chris Brown, senior director, data security at Imperva.

Thanks to our podcast sponsor, Imperva.

Face it, your data is everywhere! Imperva Data Security unifies compliance, security and privacy needs for any data store while saving you time and money. No matter where data lives, get confidence about what is happening with data, where it’s stored and who’s accessing it. Start a free trial now.

In this episode * Cloud platforms and exposure make it easier to deploy with less oversight, making mistakes easier. * There's a need for a change of mindset of product and marketing leaders to consider consequences of taking in different data types in the design phase. * There's also a need for SIEM tools and access management.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-should-cisos-be-licensed-professionals/)

Many professionals are required to obtain a license before they can do their job legally. The demands of cybersecurity professionals, especially CISOs, has become more critical as evidenced by the increasing number of regulations demanding a person oversee security and privacy controls. Should CISOs be licensed to maintain a minimum standard?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and our guest Patrick Benoit (@patrickbenoit), vp, global head of GRC and BISO, CBRE.

Thanks to this week's podcast sponsor, F5

External threats to your organization’s security are constantly evolving. Your apps need broad and preventive protection from bot attacks that cause large-scale fraud, higher operational costs, and problems for your users. And they need to be optimized for secure operation internally. Silverline Shape Defense helps you stay ahead of cyber threats and fraud. Get a free trial.

Highlights from this episode of Defense in Depth: * Almost universally, nobody liked the idea of requiring a CISO to have a license in order to practice. But, with that said, the subject stirred up a hornet's nest of discussion. * Main complaint is the job changes so drastically depending on what industry you're in. * Many argued that a license won't translate into success. Hard to tell how to put a license around someone who is managing risk, but doesn't own the risk.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-inherently-vulnerable-by-design/)

Much of what we do as practitioners is to prevent inadvertent security problems - oversights, zero-days, etc. What about inherent and unavoidable problems? When the very design of the thing requires a lack of security? What do you do then?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and our sponsored guest is Dan Woods, vp of the Shape Intelligence Center, F5.

Thanks to this week's podcast sponsor, F5.

External threats to your organization’s security are constantly evolving. Your apps need broad and preventive protection from bot attacks that cause large-scale fraud, higher operational costs, and problems for your users. And they need to be optimized for secure operation internally. Silverline Shape Defense helps you stay ahead of cyber threats and fraud. Get a free trial.

On this episode of Defense in Depth, you’ll learn: * The mere act of conducting business requires you to have certain procedures that would make you vulnerable. Simple things like taking customer information to create user accounts and processing credit cards. That's inherent to doing business, and by opening that up, it makes you vulnerable. * A lot of this inherent vulnerability comes down to having users or customers and needing to authenticate them. * When you start a business you're also accepting the inherent vulnerability and you have to ask yourself to what level can the business function having that vulnerability abused? It's all about risk appetite. * Two factor authentication sure is nice, but there has to be multiple "behind the scenes" authentications going on to verify identity continuously. * As you're collecting all these additional data points you can use that information to ask the user to verify. * Provide discounts to customers and users for good security practices. Insurance companies do this with people who prove safe driving practices. It could be a win-win for everybody. For example, with Mailchimp, they give you a discount if you enable 2FA. Why not offer a discount for a really long and complicated password? * One of the major issues is the password reset process happens through email. Email wasn't designed for critical authentication. Many hacks happen through the reset process via email.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-imposter-syndrome/)

For CISOs and other security leaders, suffering from imposter syndrome seems inevitable. How can you ever be really confident when there's an endless stream of threats and a landscape that changes without your knowledge?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and our guest David Peach (@realdavidp), CISO and head of privacy, The Economist Group.

Thanks to this week's podcast sponsor, F5.

CISOs are dealing with the increasing sophistication of cyber attackers that are taking advantage of their applications. Find out how F5 helps organizations expand their security and see the unseen by watching the F5 Security Summit webinar. View it here.

On this episode of Defense in Depth, you’ll learn: * Imposter syndrome is a feeling of not being as good as you purport to be or others perceive you to be. Almost all security professionals, especially CISOs, have moments of imposter syndrome. * The root of the problem is underestimating your contributions. * Imposter syndrome can debilitate a security professional. But the opposite is also dangerous. If you don't question your ability and think you alone can solve things and others perceive that you can do that as well, that's a disaster waiting to happen. * The relentless change of technology and threats can overwhelm a professional and feel that they can't keep up. There's a sense of you will always be behind. * It's not a sprint, nor a marathon. Security is an infinite game. There's no winning and no moment of relief, but looking at it as a journey you can see success along the way. * There is an outside pressure that CISOs know more than they actually do, and at the same time they don't want to disappoint management, the business, or the team. * Imposter syndrome can be seen as a positive when it leads to self awareness and improvement. * Be smart enough to know how little you do know and accept it, but still stay on that journey to keep learning more. * You can't teach the person who thinks they know it all. * The flipside is you rarely get congratulated for your work as a security professional.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-why-dont-more-companies-take-cybersecurity-seriously/)

With every cybersecurity breach, we still don't seem to be getting through. Many companies don't seem to be taking cybersecurity seriously. What does it take? Obviously not scare tactics.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and our guest Ben Sapiro, global CISO, Great-West LifeCo.

Thanks to this week's podcast sponsor, Sonatype.

On this episode of Defense in Depth, you’ll learn: * Even with attacks and breaches on a constant march, far too many companies operate under the "it will never happen to me" ostrich strategy. * Problem with the "I'm too small to attack" defense is you probably also have minimal security protections which also makes you far easier to attack. Far easier to penetrate 100 low defense targets than one huge target with high defenses. * Watching other companies survive a breach makes one feel as if they'll be just as resilient. * Many companies not showing interest in cybersecurity may simply not be doing appropriate risk-based analysis. * A company in a highly regulated industry has no choice but to take cybersecurity seriously. * Businesses that are highly built on trust and have a low barrier to exit often understand the need to take cybersecurity seriously. They are always cognizant of reputational risk. * Many feel that they are powerless against the onslaught of attacks and even if they do take cybersecurity seriously and spend money defending themselves it will all be a giant waste of effort. * Many people simply don't feel attached to any type of cybersecurity effort. If you're not vested in it, why care about it? * Those of us in cybersecurity forget what it feels like to not know anything about cybersecurity.

On this episode of Defense in Depth, you’ll learn: * Even with attacks and breaches on a constant march, far too many companies operate under the "it will never happen to me" ostrich strategy. * Problem with the "I'm too small to attack" defense is you probably also have minimal security protections which also makes you far easier to attack. Far easier to penetrate 100 low defense targets than one huge target with high defenses. * Watching other companies survive a breach makes one feel as if they'll be just as resilient. * Many companies not showing interest in cybersecurity may simply not be doing appropriate risk-based analysis. * A company in a highly regulated industry has no choice but to take cybersecurity seriously. * Businesses that are highly built on trust and have a low barrier to exit often understand the need to take cybersecurity seriously. They are always cognizant of reputational risk. * Many feel that they are powerless against the onslaught of attacks and even if they do take cybersecurity seriously and spend money defending themselves it will all be a giant waste of effort. * Many people simply don't feel attached to any type of cybersecurity effort. If you're not vested in it, why care about it? * Those of us in cybersecurity forget what it feels like to not know anything about cybersecurity.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-data-protection-and-visibility/)

Where is your data? Who's accessing it? You may know if you have an identity access management solution, but what happens when that data leaves your control. What do you do then?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and our sponsored guest is Elliot Lewis (@elliotdlewis), CEO, Keyavi Data.

Thanks to this week's podcast sponsor, Keyavi Data.

Our Keyavi breaks new ground by making data itself intelligent and self-aware, so that it stays under its owner’s control and protects itself immediately, no matter where it is or who is attempting access. Keyavi is led by a team of renowned data security, encryption, and cyber forensics experts. See for yourself at keyavidata.com.

On this episode of Defense in Depth, you’ll learn: * In general, all of security is based on detecting threats and stopping threats. When those two fail, and they do, what's your recourse to protect your data? * What if when your data leaves your control either accidentally or through a malicious breach, you were still able to see your data wherever it went and your data could communicate back to you its status, allowing you to control access to your data? * There are so many scenarios when data leaves you, it's impossible to protect for all scenarios. * Asset inventory is first step in the CIS 20. Just trying to get an asset inventory of equipment is difficult. An inventory of data is near impossible especially when you may be pumping out a terabyte of data a day. * Ideal situation is to protect data proactively, as it's being created. * The ultimate goal is to have visibility of your data in perpetuity, for the life of the data, and you can decide when to destroy it even when it's no longer within the confines of your greater network and ecosystem. * Governing your network, your applications, the rules, and the data is half the battle. * Data visibility also allows you to make informed decisions as a business and can provide the answers your legal team will need in case there's a breach. * You want the data protection and visibility schema to be platform and ecosystem independent. If data is taken out of the ecosystem, then the protection and visibility is moot. * A good precursor to this is digital rights management or DRM. They have figured out how to manage data from being copied and manipulated and they can place controls on it. The limiting factor though is it's platform dependent.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-whats-an-entry-level-cybersecurity-job/)

Naomi Buckwalter, director of information security at Energage analyzed one thousand random information security job posts on LinkedIn. The most notable trend she found was that 43% of the posts had CISSP and 5-year experience requirements for entry level positions. Are companies trying to lowball cybersecurity professionals, or do they simply not know what an entry level cybersecurity job is.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and our guest is Joseph Carrigan (@JTCarrigan), senior security engineer at Johns Hopkins University Information Security Institute, and co-host Hacking Humans podcast.

Thanks to this week's podcast sponsor, Keyavi Data.

Our Keyavi breaks new ground by making data itself intelligent and self-aware, so that it stays under its owner’s control and protects itself immediately, no matter where it is or who is attempting access. Keyavi is led by a team of renowned data security, encryption, and cyber forensics experts. See for yourself at keyavidata.com.

On this episode of Defense in Depth, you’ll learn: * There has been an ongoing trend for companies to post "entry level but experience required" job listings for cybersecurity professionals. * This is self-defeating for companies because the positions don't get filled. And for true entry level people, they get discouraged. They feel it's impossible to get into the industry. This can drive them away from cybersecurity which hurts the entire industry. * Others would argue that we shouldn't even have this conversation because there is no such thing as an entry level position. Like there are no entry-level doctors. You must have some type of training or experience to do this job. * There's no doubt that CISOs fight more for headcount than they do overall dollars. And if they get a limited headcount, they're going to want to get as much talent as they possibly can with that limited number of positions they can fill. * Security is a layer on top of IT, engineering, or development. For that reason it can be seen as mid-level experience or above, simply because security is a specialization. * Is this behavior of shooting so high for an entry-level cybersecurity role causing the cybersecurity skills gap? * Best way to prove your value to a hiring cybersecurity professional is to setup your own home lab. * The skill that is hard to put on a resume or to explain in a job listing is non-linear thinking. But that's essentially what you're looking for with an entry-level cybersecurity hire.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-securing-digital-transformations/)

Digital transformation. It's definition is broad. Meaning securing it is also broad. But there are some principles that can be followed as companies undergo each step in a deeper dive to make more and more of their processes essentially computerized.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and our guest is Paul Asadoorian (@securityweekly), founder & CTO, Security Weekly, and chief innovation officer, Cyber Risk Alliance.

Thanks to this week's podcast sponsor, Keyavi Data.

Our Keyavi breaks new ground by making data itself intelligent and self-aware, so that it stays under its owner’s control and protects itself immediately, no matter where it is or who is attempting access. Keyavi is led by a team of renowned data security, encryption, and cyber forensics experts. See for yourself at keyavidata.com.

On this episode of Defense in Depth, you’ll learn: * Digital transformation is about relying on computing technology for more integral processes and aspects in our daily work lives. * Lots of debate on the definition of digital transformation and as well securing digital transformations. * Definition: A targeted change to process and technology for the benefit of the people. * Definition: increasing levels of interoperability of information. * We heard the recurring argument of the need for security to have a seat at the table at the beginning of a digital transformation, and not at the end. But at the same time reality sunk in and it was argued that security doesn't get to dictate that. And if security tried to, it would create a greater wedge with the business. * When security is brought in at the end though, security has no option but to disrupt the business. Then no one is happy. * Digital transformation simply introduce new risks, often greater risk. If the point is to integrate more of your processes, then that integrates the risk as well. * If you're undergoing a true transformation, you are looking at core processes and saying, "What new tech facilitates, streamlines, and/or actualizes these core processes?" You no longer have to settle for shopping for a solution and then smashing your processes up against it. * Your security tools should also undergo a transformation. That includes a transformation in monitoring as well.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-leaked-secrets-in-code-repositories/)

Secrets, such as passwords and credentials, are out in the open just sitting there in code repositories. Why do these secrets even exist in public? What's their danger? And how can they be found and removed?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and our sponsored guest is Jérémy Thomas, CEO, GitGuardian.

Thanks to this week's podcast sponsor GitGuardian.

GitGuardian empowers organizations to secure their secrets - such as API keys and other credentials - from being exposed in compromised places or leaked publicly. GitGuardian offers a threat intelligence solution focused on detecting secrets leaked on public GitHub and an automated secrets detection solution which tightly integrates with your DevOps pipeline.

On this episode of Defense in Depth, you’ll learn: * Putting passwords and other credential information inside of code simply happens. It is done by developers for purposes of efficiency, laziness, or simply forgot to take it out. * Given that exposing secrets is done by developers, these secrets appear in code everywhere, most notably in public code repositories like GitHub. * Exposed credentials can appear in SIEMS as it's being exported from the developers' code. * There is a shared responsibility model and cloud providers do have some ability to scan code, but ultimately code you put in your programs is your responsibility. * Scanning public code repositories should be your first step. You don't want to be adding code that has known issues. * Next step is to scan your own code and get alerts if your developers are adding secrets (wittingly or unwittingly) in their code. If you alert in real-time, it fits naturally within the DevOps pipeline and they will improve their secure coding skills. * Another option to deal with exposed secrets is to sidestep the problem completely and put in additional layers of security, most notably multi-factor authentication (MFA). A great idea, and yes, you should definitely include this very secure step, but it doesn't eliminate the problem. There are far too many authentication layers (many automated) for you to put MFA on everything. There will always be many moments of exposure.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-measuring-the-success-of-your-security-program/)

How does a CISO measure the performance of their security program? Sure, there are metrics, but what are you measuring against? Is it a framework or the quality of protection? How do you tell if your program is improving and growing?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and our sponsored guest is Chad Boeckmann (@SDS_Advisor), CEO, TrustMAPP.

TrustMAPP delivers continuous, automated Security Performance Management, a real-time view of your cybersecurity maturity. TrustMAPP tells you where you are, where you’re going, and what it will take to get there. TrustMAPP lets you manage security as a business, quantifying and prioritizing remediation actions and costs.

On this episode of Defense in Depth, you’ll learn: * The process is very systematic. Start with knowing your risks, how you're going to track them, and the controls you're going to put them in place to manage them. Simple to say, hard to do. * Security risk is just one of a multitude risks a business faces. * Data's whereabouts is a moving target. Having confidence in its location and protections is key to managing overall risk. * Constantly be asking who has access to the data and what communications processes are you using to share that information between humans and machines. * Discuss with leadership as to how you will judge success and what metrics you will use. C-suite will need to lead the discussion with security providing guidance as to what they can and can't measure. * If you're measuring security's performance this is a great opportunity for security to tell its story and prove its value, ultimately setting it up for increased budget and participation from others. * An informal metric for success could be how often is security getting invited to informal meetings. * Overall positive sentiment of security by non-security employees. * How well are you able to build (are people eager to work with you?) and maintain your staff? * Another "out of the box" metric to consider are opportunity costs. How many contracts are you losing because you were incapable of meeting a potential customer's security standards? * Strong debate as to what is the goal of a security program: Risk reduction or risk management? It's very possible that you are currently managing risk well and the additional cost to reduce risk is not necessary.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-privacy-is-an-uphill-battle/)

Privacy is an uphill battle. The problem is those gathering the data aren't the ones tasked with protecting the privacy of those users for whom that data represents.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and our guest is Dave Bittner (@bittner), host, The CyberWire Podcast.

Thank to our episode sponsor, TrustMAPP.

TrustMAPP delivers continuous, automated Security Performance Management, a real-time view of your cybersecurity maturity. TrustMAPP tells you where you are, where you’re going, and what it will take to get there. TrustMAPP lets you manage security as a business, quantifying and prioritizing remediation actions and costs.

On this episode of Defense in Depth, you’ll learn: * Marketers, the ones often collecting the data, have no incentive to not gather more. The only thing holding them back, barely, are newly growing privacy regulations. * Security professionals are tasked with protecting privacy but they're not usually on the front lines of data collection and are often brought in after the data has been collected. * The public has become numb to the abuse of their privacy. A little is being chipped away at the time that they either don't know they're being abused or it appears to be so slight they don't even care. They see the benefits of sharing far outweighing the negatives. * GDPR is large and very difficult to comply with. And although it only affects site visitors from Europe, most site owners are deploying GDPR controls system-wide for all visitors for fear of making a mistake while at the same time realizing that similar regulations will launch in other parts of the world.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-legal-protection-for-cisos/)

What's the legal responsibility of a CISO? New cases are placing the liability for certain aspects of security incidents squarely on the CISO. And attorney-client privilege has been overruled lately too. What does this mean for corporate and for CISO risk?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and our guest is Evan Wolff, partner at Crowell & Moring.

Thank to our episode sponsor, TrustMAPP.

TrustMAPP delivers continuous, automated Security Performance Management, a real-time view of your cybersecurity maturity. TrustMAPP tells you where you are, where you’re going, and what it will take to get there. TrustMAPP lets you manage security as a business, quantifying and prioritizing remediation actions and costs.

On this episode of Defense in Depth, you’ll learn: * We repeatedly joke about Davi Ottenheimer's comment that the CISO has held the moniker of "designated felon" in American risk mitigation. * Big piece of advice that was repeated throughout the episode is to have an employment contract. * In the employment contract you want an exit strategy that allows you to leave if you think a situation is not tenable or the company is asking you to do something that you believe to be unethical. It gives you an opportunity to leave without any blame assigned. * The cc field is your friend. If you don't want to be seen as the only one "in the know" take advantage of making sure key people are also in the loop. * We heard one unbelievable story of an employment contract where it was clear that the CISO would be the "designated felon" should there be any breach. This was put in place to protect the executive team. The contract offered financial security for two years post breach. We all agreed this was insane and had never heard of anything like that before. * Be wary of being forced to take on personal ownership of security issues. A CISO is responsible, not accountable.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-xdr-extended-detection-and-response/)

Is XDR changing the investigative landscape for security professionals? The "X" in XDR extends traditional endpoint detection and response or EDR to also include network and cloud sensors. Having this full breadth, XDR can contextualize alerts to tell a more cogent story as to what's going on in your environment.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and our guest is Dave Bittner (@bittner), host, The CyberWire.

Thanks to our sponsor, Hunters.

Attackers always find new ways to bypass organizational defenses. While their traces hide in the data, they’re also extremely difficult to detect. Hunters.AI is a context-fueled XDR solution that harnesses top-tier threat hunting expertise and ML to autonomously detect, investigate and correlate attack findings across cloud, network, and endpoint.

On this episode of Defense in Depth, you’ll learn: * XDR extends traditional endpoint detection and response or EDR to also include network and cloud sensors. * XDR is viewed as a comprehensive solution that rolls up all your critical feeds, sensors, and analytics. * Having this full breadth, XDR can contextualize alerts to tell a more cogent story as to what's going on in your environment. * If you've got a greenfield security program (essentially it's non existent), XDR is a no-brainer. But for everyone else, which is most of us, rolling out XDR is not as clear cut a decision. How does it integrate with your existing tech stack? * Lots of question as to why do you need a SIEM if you have XDR? But, most responded that the two technologies are complimentary. Where XDR becomes redundant is if you have SIEM + SOAR + XDR + NDR. * XDR's real power is the ability to give you some of the investigative details rather than just telling you that somebody breached a certain endpoint. But it can connect the dots and explain that a certain breach also resulted in a certain action. This greatly reduces the time your SOC needs to spend investigating cases. * Don't though be fooled with solutions that sell purely on reducing time and effort. You're only going to have that if you have useful integrations.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-calling-users-stupid/)

Many cybersecurity professionals use derogatory terms towards their users, like calling them "dumb" because they fell for a phish or some type of online scam. It can be detrimental, even behind their back, and it doesn't foster a stronger security culture.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and our guest Dustin Wilcox, CISO, Anthem.

Thanks to our sponsor, Hunters.

Attackers always find new ways to bypass organizational defenses. While their traces hide in the data, they’re also extremely difficult to detect. Hunters.AI is a context-fueled XDR solution that harnesses top-tier threat hunting expertise and ML to autonomously detect, investigate and correlate attack findings across cloud, network, and endpoint.

On this episode of Defense in Depth, you’ll learn: * Security people have notoriously had a "better than them" attitude towards their users who they view as the ones causing all the problems and making their lives more difficult. * Calling users stupid for making a "mistake of effort" even if it's behind their back does not foster a bond with the security team. It fosters the us vs. them attitude. * Security professionals will have a lot more success if they understand why users do the things they do. Once there is that understanding, then cybersecurity will better be able to design systems that accommodate users. * About a third of your users confidently believe they're following the right cybersecurity procedures. That discrepancy is not the fault of the users, it's the fault of cybersecurity's education of users. * Security can always be more effective in offering up the right tools and the correct education. * Security awareness must begin with good service and process design. * Phishing tests are pointless to determine security effectiveness. That's because no matter how low your click rates go, someone can always create a more creative test that will send them soaring back up again. * If your defense in depth strategy is so poorly designed that your company can be compromised by the simple click of a phish, then you've got a poorly configured security stack. * Security professionals' jobs exist because of their users. If there was no organization and users, then there would be no need for security professionals. * Quoting Albert Einstein: "If you judge a fish by his ability to climb a tree, he will live his whole life thinking he is stupid.” * Look at user mistakes as an education moment, not an opportunity to put them down. If you educate them, they'll go onto educate others as well. Mistakes can actually be very beneficial.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-is-college-necessary-for-a-job-in-cybersecurity/)

Where is the best education for our cyber staff of the future? Where does college fit in or not fit in?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and our guest Dan Walsh, CISO, Rally Health.

Thanks to our sponsor, Hunters.

Attackers always find new ways to bypass organizational defenses. While their traces hide in the data, they’re also extremely difficult to detect. Hunters.AI is a context-fueled XDR solution that harnesses top-tier threat hunting expertise and ML to autonomously detect, investigate and correlate attack findings across cloud, network, and endpoint.

On this episode of Defense in Depth, you’ll learn: * Years ago most would say a college degree is necessary, but it appears the ROI for exorbitant college education simply doesn't deliver like it used to. * Tons of valuable online courseware can deliver a targeted education for individuals wanting to start a career in cybersecurity. * If organizations believe these first two statements to be true, then why are they putting down a college degree as a requirement for jobs in cybersecurity? * Is requiring a college degree a false and elitist narrative that doesn't drive better cybersecurity talent? * With such a stringent requirement, it detracts many people, including women and minorities, who may not have college degrees to pursue cybersecurity roles. * Most college courseware in computer science is often quickly outdated. But that doesn't speak to all colleges. Some that specialize in cybersecurity are doing their best to stay current. * Those arguing the need for college explain it teaches critical thinking and the desire to always keep learning. * Does the lack of having a college degree prevent an individual from moving up the ranks in cybersecurity leadership? * The college degree requirement may be arbitrary or it may be there because of management's jealousy. They had to have a college degree when they joined so everyone else should as well. * A college degree doesn't necessarily mean you'll be a great technician.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-when-red-teams-break-down/)

What happens when red team engagements go sideways? The idea of real world testing of your defenses sounds great, but how do you close the loop and what happens if it's not closed?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and our sponsored guest, Dan DeCloss, founder and CEO, PlexTrac.

Thanks to this week’s podcast sponsor, PlexTrac.

PlexTrac is a revolutionary, yet simple, cybersecurity platform that centralizes all security assessments, penetration test reports, audit findings, and vulnerabilities into a single location. PlexTrac vastly improves the risk management lifecycle, allowing security professionals to generate better reports faster, aggregate and visualize important analytics, and collaborate on remediation in real-time.

On this episode of Defense in Depth, you’ll learn: * Don't make the mistake of red teaming too early. If you don't have your fundamental security program in place, you'll be testing out non-existing defenses. * If you're just starting to build up your security program, conduct a vulnerability scan and do some basic patch management. * A red team exercise exists to discover risks you didn't even know about and couldn't have predicted in your threat model exercises. * Have a plan of what you're going to do after the red team exercise. Just discovering you've got problems with no plan to remediate them will not only be a waste of money, but will also breed discontent. * Don't red team just to fill out an audit report. You can do a vulnerability scan for that. * Consider moving the red team to purple to actually help the blue team remediate the findings. * If you don't have a plan for remediation you'll find yourself running the same red team and filling out the same report. * Prioritize! The red (now purple) team can greatly help along with those who've assessed business risks. * First to remediate are the ones that are high impact and easy to execute. The rest is determined by an analysis of likelihood and impact.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-what-cyber-pro-are-you-trying-to-hire/)

Do companies hiring cybersecurity talent even know what they want? More and more we see management jobs asking for engineering skills, and even CISO jobs with coding requirements. What's breaking down?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and our guest Liam Connolly, CISO, Seek.

Thanks to this week's podcast sponsor, Salt Security.

Salt Security protects the APIs at the core of SaaS, web, and mobile applications. By using patented behavioral protection Salt Security automatically and continuously discovers and learns the granular behavior of each unique API and stops attacks. In 2020 Salt Security was named a Gartner Cool Vendor in API Strategy.

On this episode of Defense in Depth, you’ll learn: * The poor focus of cybersecurity job listings often exposes either the poor understanding or lack of maturity of a company's information security program. * We often see management cyber jobs asking for engineering skills and vice versa. * Job listings can also portray the "last guy" syndrome. Those are the job listings that tack on desired skills the last person did not have. * When you see too many requirements it comes off as a wish list. It's not what is required, it's more of a question as to how many boxes can a candidate check off. * There can be serious harm to a company's ability to hire if they throw down too many requirements or even optional items. People who are truly required for the position you want may never apply because they'll be scared off by the other skills required or desired. * CISOs are often hired by non security people and as a result they don't have a full understanding of what type of CISO they want. As a result it's often hard to find two similar CISO job listings. * While CISO technical competencies are desired, it's clear that once hired a CISO will not be showing off their technical expertise. As a result, there's a lot of debate as to how much technical skill a CISO really needs. The job requires management, influencing, and communications. * Many hiring teams have a hard time parsing out the types of security people they need to build out a security team. That's why you get a single job listing that appears to want to hire five different types of security people. * If a CISO isn't given the budget and authority to hire a staff to fill all the necessary gaps for the company's security program, they will become fed up and leave. That starts the whole process again. * Many debate that job titles in job listings are just there to massage the ego. But if compensation doesn't match the title, then they realize the title is just for show.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-junior-cyber-people/)

There are so few jobs available for junior cybersecurity professionals. Are these cyber beginners not valued? Or are we as managers not creating the right roles for them to improve our own security?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and guest Naomi Buckwalter (@ineedmorecyber), director of information security & privacy at Energage.

Thanks to this week's podcast sponsor, Salt Security.

Salt Security protects the APIs at the core of SaaS, web, and mobile applications. By using patented behavioral protection Salt Security automatically and continuously discovers and learns the granular behavior of each unique API and stops attacks. In 2020 Salt Security was named a Gartner Cool Vendor in API Strategy.

On this episode of Defense in Depth, you’ll learn: * There are tons of newbies eager to work in cybersecurity. The shortcoming is not the available pipeline, but a lack of headcount and managers' willingness to train and find appropriate assignments. * Because headcount is often the limitation to hiring, leaders will opt to hire the most senior person they can get. * Common feeling is hire one experienced person and stress them out rather than hire three junior people and train them. Problem with the former is if you stress that experienced person they will leave and tell others not to work there. * There is plenty of good junior-level cybersecurity work, such as asset management cleanup, PII discovery, procedure documentation, filling out security questionnaires, scrubbing and tuning out false positives from alerting systems, reviewing vendor contracts, patch verification, following up on vulnerability management with other teams, launching and managing vulnerability scans, interviewing for shadow IT installations, working with help desk for user account remediation, and scanning logs for anomalies.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-trusting-security-vendor-claims/)

Do security vendors deliver on their claims and heck, are they even explaining what they do clearly so CISOs actually know what they're buying?

Check out this post and the Valimail survey for the basis of our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and guest Lee Parrish (@LeeParrish), CISO, Hertz.

Thanks to this week's podcast sponsor, AttackIQ.

AttackIQ, the leading independent vendor of breach and attack simulation solutions, built the industry’s first Security Optimization Platform for continuous security control validation and improving security program effectiveness and efficiency. AttackIQ is trusted by leading organizations worldwide to plan security improvements and verify that cyberdefenses work as expected, aligned with the MITRE ATT&CK framework. On this episode of Defense in Depth, you’ll learn: * From those surveyed by Valimail survey, a third to a half didn't believe that vendors did a good job explaining what their product does, or that the product actually performed, or there was any way to actually measure that performance. * Many questioned those numbers because they feel many security buyers still fall for security vendors' boastful claims. Both can actually be true. * Stunned behavior at a trade show is not the indicator of knowledge and susceptibility to vendor pitches. * When you're under the gun as a security professional to produce results you often become victim to security vendor claims because you want to deliver on demands from the business. * By nature, CISOs should be skeptical about vendor claims and information within their own environment. * There's a battle between those vendors truly trying to deliver value and those who are using their marketing savvy to sway industry thinking. * Don't place all the blame on the vendors. CISOs still have trouble understanding their requirements, risk, and priorities. Many are guilty of engaging in "random acts of security". * Claims can often be more trustworthy if the vendor is willing to explain what they can't do.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-how-vendors-should-approach-cisos/)

"How do I approach a CISO?" It's the most common question I get from security vendors. In fact, I have another podcast dedicated to this very question. But now we're going to tackle it on this show.

Check out this post for the basis of our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and guest Ian Amit (@iiamit), CSO, Cimpress.

Here also is my original article with Allan Alford when he first launched this engage with vendors campaign.

Thanks to this week's podcast sponsor, Sonrai Security.

Identity and data access complexity are exploding in your public cloud. 10,000+ pieces of compute, 1000s of roles, and a dizzying array of interdependencies and inheritances. Sonrai Security delivers an enterprise cloud security platform that identifies and monitors every possible relationship between identities and data that exists inside your public cloud.

On this episode of Defense in Depth, you’ll learn: * All CISOs are different so any advice we provide will vary from CISO to CISO. Plus, we have an entire other show, CISO/Security Vendor Relationship Podcast, dedicated to this very topic. * We acknowledge that this is tough because to be really on target you need to know what the CISO has, what their mix of products are, and how your product could work in their current security maturity and mix of security products and processes. It's all a very tall order for a security vendor. * Vendors must stop thinking of themselves as point solutions, but rather how they fit into the overall makeup of a security program. You're not coming in with a blank slate. How do you interoperate with what's existing? * There's unfortunately the trend of the people who make the contact, then initiate a meeting, and hand off to someone else. CISOs do not welcome that kind of engagement, although it may be very cost effective for security vendors to hire junior people to make those contacts and hand offs. * Lots of argument about the efficacy and the acceptance of cold calling. Those who claim they don't like it are often working at organizations that do it repeatedly to great success. * The pushy salesperson who eventually gets through after repeated attempts even when they're told no may show success, but they don't calculate all the people they've angered and the word-of-mouth negativity that has resulted from that behavior. If you push beyond a request to stop, the worse that can happen is your reputation will be destroyed. * CISOs are more receptive to market pull into your organization. That can happen through traditional marketing, content marketing, podcasts, analyst reviews, and word-of-mouth. Problem is these techniques don't leave any room for salespeople to operate.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-secure-access/)

What is the Holy Grail of secure access? There are many options, all of which are being strained by our new work from home model. Are we currently at the max?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series and Allan Alford (@AllanAlfordinTX). Our sponsored guest is Rohini Kasturi, chief product officer, Pulse Secure.

Thanks to this week’s podcast sponsor, Pulse Secure.

Pulse Secure offers easy, comprehensive solutions that provide visibility and seamless, protected connectivity for hybrid IT in a Zero Trust world. Over 24,000 enterprises entrust Pulse Secure to empower their mobile workforce to securely access applications and information in the data center and cloud while ensuring business compliance.

On this episode of Defense in Depth, you’ll learn: * Multiple technologies, such as VPN, split-tunnel VPN, VDI, SASE, EDR, and secure management, are used in attempts to insure secure access. But given that secure access isn't just about managing endpoints, but users, you also have to look at IAM. * We look to conditional access to provide more support than just full VPN access. * Argument that we are moving away from endpoints to identity as that's the new perimeter. * SASE solution blocks by default, instead of allows by default, and requires permission for access. User is secured dynamically based on a combination of identity and device. * Would be great if secure access solutions were universal, but they vary country by country based on costs, availability, and regulations. * Secure access models must be user experience first. One possible play that works in this way is IAM + SASE + EDR + secure management. * Another factor that prevents the one-size fits all model for secure access is the complexity of stacks.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-infosec-fatigue/)

Have we reached peak InfoSec fatigue? Revolving CISOs and endless cyber recruitment OR the fact that we're spending more money to reduce even greater risk. Is it all leaving our grasp?

Check out this post for the basis of our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and guest Helen Patton (@OSUCISOHelen) CISO, The Ohio State University.

Thanks to this week's podcast sponsor, Sonrai Security.

Identity and data access complexity are exploding in your public cloud. 10,000+ pieces of compute, 1000s of roles, and a dizzying array of interdependencies and inheritances. Sonrai Security delivers an enterprise cloud security platform that identifies and monitors every possible relationship between identities and data that exists inside your public cloud.

On this episode of Defense in Depth, you’ll learn: * Are we sliding in our effort to get ahead of security issues? There's a sense the tools and our ability isn't keeping up with the onslaught. * Are we able to prove risk reduction to show that our efforts are successful? * Those people who don't burn out are the ones who thrive on the technical and political challenges of cybersecurity. * Disagreement on how you lead a discussion. Should it be story-based or data-based? * Classic complaint about cybersecurity is success is measured by the absence of activity. * Preventative security is not easily quantifiable as reactive security. * CISOs have to step up and show evidence of security's success in the most understandable and digestible format. Suggested measures and metrics: likelihood and impact, business impact analysis, security program maturity curve, framework compliance, pen test results, and threat modeling. * FUD (fear, uncertainty, and doubt) may be effective in the short run, but it's exhausting. It never works in the long term. * Approach cybersecurity altruistically. If it benefits you and those around you, then it's worth doing. * Lean on security vendors to help you show the value of their product. The business impact will be on the CISO's shoulder, but the vendor should help build the case.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-securing-a-cloud-migration/)

You're migrating to the cloud. When did you develop your security plan? Before, during, or after? How aware are you and the board of the cloud's new security implications? Does your team even know how to apply security controls to the cloud?

Check out this post for the basis of our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and sponsored guest Sandy Bird, CTO and co-founder, Sonrai Security.

Sandy was the co-founder and CTO of Q1 Labs, which was acquired by IBM in 2011. At IBM, Sandy became the CTO for the global security business and worked closely with research, development, marketing, and sales to develop new and innovative solutions to help the IBM Security business grow to ~$2B in annual revenue.

Thanks to this week's podcast sponsor, Sonrai Security.

Identity and data access complexity are exploding in your public cloud. 10,000+ pieces of compute, 1000s of roles, and a dizzying array of interdependencies and inheritances. Sonrai Security delivers an enterprise cloud security platform that identifies and monitors every possible relationship between identities and data that exists inside your public cloud.

On this episode of Defense in Depth, you’ll learn: * You can't just migrate to public cloud and secure things like you secure your on-premise servers and applications. You have to think cloud-native in all security decisions. * Cloud migrations intensify the focus between data and identity. * "Security as an afterthought" is never a good plan. Those who succeed build security into the migration. Don't let IT broker a deal to migrate to cloud and then bring in cyber after the fact. * In the cloud, knowing where your data is one step, securing the data is another. * There's a multitude of variances with data. There are the API controls on data, who has access through those APIs, is the data cloned or cached, and how are permissions being adjusted to that data? * Start by knowing who and what should access your data and build your controls from there. * The people side of securing cloud migration is critical. If your staff is not properly trained, a single mistake can be extremely expensive. * Speeds in the cloud, especially if you've got a DevOps and CI/CD approach, can make problems move at lightening speed. There's a need for automation and to continuously monitor your controls and coverage. Get ahead of problems. * DevOps learned the fail fast technique, but also the ability to recover quickly. If security wants to play as well, they have to develop the same strategy and tools.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-api-security/)

APIs are gateways in and out of our kingdom and thus they're also great access points for malicious hackers. How the heck do we secure them without overwhelming ourselves?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and sponsored guest, Roey Eliyahu, CEO, Salt Security.

Salt Security protects the APIs at the core of SaaS, web, and mobile applications. By using patented behavioral protection Salt Security automatically and continuously discovers and learns the granular behavior of each unique API and stops attacks. In 2020 Salt Security was named a Gartner Cool Vendor in API Strategy.

On this episode of Defense in Depth, you’ll learn: * The skill set needed to secure APIs is different than web security. * The move towards the cloud, DevOps, and the need to have security tools talk to each other has brought a lot more attention to the need for API security. * Like in all areas of security, just knowing what you've got is a struggle. Same is true with APIs. * Just knowing what APIs you have is not enough. You must know their functionality. Map your APIs to the systems and the data their transmitting. * How aware are your developers of the pitfalls of API misuse? * There's a myriad of security options but start with strong authenticate using hash-based message authentication. * Much of the advice we got was simply shrinking the API attack surface. This can be done by either limiting the functionality of the API or removing unused APIs. * The "review the code" advice that we heard often is sadly not realistic. APIs are resistant to both automatic and manual code review. * API security seems like a 300 or 400 level security effort. Smaller companies that don't have a security operations center (SOC) may simply not be able to handle it and will need to outsource their API security and SOC needs to a third party or managed security service.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-shared-threat-intelligence/)

We all know that shared intelligence has value, yet we're reticent to share our threat intelligence. What prevents us from doing it and what more could we know if shared threat intelligence was mandated?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and sponsored guest, Joel Bork (@cincision), senior threat hunter, IronNet Cybersecurity.

Thanks to this week's podcast sponsor, IronNet Cybersecurity.

To combat sophisticated cyber threats, companies are increasingly adopting collective defense strategies to actively share intelligence with peer organizations to improve the detection capabilities of the collective. Through faster sharing of behavioral analytics, signature-based, and human threat insights, organizations can more effectively spot malicious activity and reduce attacker dwell time. More on IronNet Cybersecurity.

On this episode of Defense in Depth, you’ll learn: * We all benefit from sharing threat intelligence, so why don't we do it? * If threat data is public, is it useful? The argument is that if the good guys know about the threat intelligence, then all the bad guys know as well. But that's if it's in a public forum. * If threat intelligence was shared in a more rapid, comprehensive, and secure manner it would have more utility. * Sometimes the "intelligence" a company first gets is just a data feed. * There has to be a greater discussion of the risks of sharing as compared to the upside. Often, it's so easy to shut the doors and not share with the benefit never calculated into the equation. * When an organization is in the middle of their security maturity curve, they hold all their data as close to their chest as possible. As they continue on their journey and continue to learn lessons along they way, they begin to understand that collaboration will help the community as a whole - including themselves. * Threat data is really not what professionals need. What they need is intelligence. And this requires a way to onboard and make sense of the data on its own and in aggregate and over time. * Each of us are collecting different pieces of the threat landscape puzzle. If someone doesn't provide their piece, then we have an incomplete puzzle and there are now holes in our knowledge and ability to protect ourselves. * Threat intelligence does not hold the same weight for every user. What's valuable to someone may not be of value to another. And you may be holding onto that data that you don't necessarily think is valuable. * You want threat intel to be actionable, not necessarily responding automatically. * We spoke of threat intel with the analogy of animals traveling in herds for protection. The attackers often pick off the weak ones, but when everyone is working together, the stronger animals can actually protect the weak. * Even with everything we know and value with shared threat intel, there is still a ton of paranoia around sharing. While there is lots of discussion about data not being identifiable, most choose to opt out of sharing threat intel.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-drudgery-of-cybercrime/)

Why does the press persist on referring to all cyber breaches as sophisticated attacks? Is it to make the victim look less weak, or do they simply not know the tedium that's involved in cybercrime?

Check out this post by Brian Krebs for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and guest Steve Zalewski, deputy CISO, Levi Strauss.

Thanks to this week's podcast sponsor, IronNet Cybersecurity.

To combat sophisticated cyber threats, companies are increasingly adopting collective defense strategies to actively share intelligence with peer organizations to improve the detection capabilities of the collective. Through faster sharing of behavioral analytics, signature-based, and human threat insights, organizations can more effectively spot malicious activity and reduce attacker dwell time. More on IronNet Cybersecurity.

On this episode of Defense in Depth, you’ll learn: * There's a dichotomy between how the press glorifies cybercrime as being "sophisticated" when the reality is much of cybercrime is drudgery. * Most cybercrime is under a pay-for-hire or a web-based service model. Cybercriminals have to deal with many of the same business-related issues we all do, such as support, infrastructure, customer relations, and sales. * Given that the cybercriminals are usually doing work for someone else, they have customers and those customers will often complain if they are not getting the expected service. * There was question if cybercrime does pay. It seemed that if you had some basic technical talents then legitimate InfoSec was a far more lucrative field that would probably offer benefits that cybercrime couldn't offer. * The paper states that low-skilled administrators often don't know much about the systems they maintain. This would lead one to believe they're also far removed from the criminal activity. * Many of these claims of the boredom of cybercrime can be made of the InfoSec community as well. * Once you understand that cybercrime is a business with a need for ROI like any other business, the goal in protecting oneself is to simply make it too costly and not financially attractive to be hacked.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-security-budgets/)

How do you calculate a security budget? Is it a percentage of the IT budget? Something else? And why does it grow so drastically after a breach?

Thanks to this week's podcast sponsor, IronNet Cybersecurity.

To combat sophisticated cyber threats, companies are increasingly adopting collective defense strategies to actively share intelligence with peer organizations to improve the detection capabilities of the collective. Through faster sharing of behavioral analytics, signature-based, and human threat insights, organizations can more effectively spot malicious activity and reduce attacker dwell time. More on IronNet Cybersecurity.

On this episode of Defense in Depth, you’ll learn: * The general consensus among the community is cybersecurity is a spend it now or spend more later decision. * While everyone wants to find a metric to determine how much to spend on cybersecurity, there doesn't seem to be any that are useful. * The CISO's job is to provide data about risks so the business can make the decision about cybersecurity spending. * Most assume that after a breach there's more cybersecurity budget, but what you get first is cooperation. * Look at security as a market differentiator. What if you could withstand a cyber attack but your competition couldn't? Or possibly you could deliver a higher level of reliability to your customers. How would your business be perceived by the market? * A business impact analysis calculator can help understand your risk levels. Allan Alford has one his site. * Many felt the biggest cost to a company suffering a breach isn't loss of data or the regulatory fines, but the damage to the company brand. * The cost of proactive protection always beats the cost of suffering a data breach. * One listener recommended that MBA programs should have a breach case study as part of their curriculum.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-role-of-the-biso/)

What is a business information security officer or BISO? Do you need one? Is it just an extension of the CISO or is it simply taking on the business aspect of the CISO role?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and guest Nicole Dove (@IssaUrbanGirl), BISO, ADP, and host of Urban Girl Corporate World podcast.

Thanks to this week's podcast sponsor, Deep Instinct.

Deep Instinct is changing cybersecurity by harnessing the power of Deep Learning to prevent threats in zero time. Deep Instinct’s on-device, solution protects against zero-day, APT, ransomware attacks, and against both known and unknown malware with unmatched accuracy and speed. Find out more about the solution’s wide covering platform play.

On this episode of Defense in Depth, you’ll learn: * A BISO becomes very valuable where they can be mapped to a specific business unit (by locale or business line). * The BISO role has become important because practically all companies are reliant on data and technology. * The BISO must have power to do their job. That requires autonomy and decision making ability. * Another way to describe a BISO is as a senior business analyst with a security focus. * From CISO to project manager, roles change often for a BISO. * Geo-aligned positions for BISOs have become extremely valuable in light of different and growing territorial regulations. * BISO is a good role for a wannabe CISO. * Only large companies have room for a BISO. * A BISO who can cozy up to a particular business units sales strategy is of enormous value. * Make sure the BISO is actually bringing value and not just acting as a gatekeeper between security and the business.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-shared-accounts/)

As bad as all security professionals know, shared accounts are a fact in the business world. They still linger, and from an operational standpoint they're hard to secure and get accountability. Why are they still around and what can be done about them?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and sponsored guest Jake King (@jakeking), CEO, Cmd.

Thanks to this week's podcast sponsor, Cmd.

Cmd provides a lightweight platform for hardening production Linux. Small and large companies alike use Cmd to address auditing gaps, implement controls that keep DevOps safe, and trigger alerts on hard-to-find threats. With out-of-the-box policies that make setup easy, Cmd is leading the way in native protection of critical systems.

On this episode of Defense in Depth, you’ll learn: * As much as it makes security professionals cringe, shared accounts are a business reality that can't be avoided. * Certain business processes force shared accounts to exist, but that doesn't mean as a security professional you shouldn't grill to find out why the shared account exists and if there's a way you can remove that shared privilege. * Get an inventory of your shared accounts. Also, you can do this with mapping credentials with location information. * Time pressures in a physical environment often force shared accounts. * You need to shine a light on shared accounts even if they're not going to go away. It's part of your GRC (governance, risk, and compliance) program. * There are compensating controls one can put around shared accounts such as password rotation, monitoring usage, and alerts. * Privileged access management (PAM) is the favorite solution for dealing with shared accounts. Often you don't need compensating controls if you have a dynamic PAM solution in place. * The need for accountability is key here. If you don't have an equal understanding of its importance then those eventual issues are simply going to magnify.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-bug-bounties/)

What is the successful formula for a bug bounty program? Should it be run internally, by a third party, or should you open it up to the public? Or, maybe a mixture of everything?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and guest Justin Berman (@justinmberman), head of security, Dropbox.

Thanks to this week's podcast sponsor, Cmd.

Cmd provides a lightweight platform for hardening production Linux. Small and large companies alike use Cmd to address auditing gaps, implement controls that keep DevOps safe, and trigger alerts on hard-to-find threats. With out-of-the-box policies that make setup easy, Cmd is leading the way in native protection of critical systems.

On this episode of Defense in Depth, you’ll learn: * Like red teaming, you need outside eyes looking at your environment and vulnerabilities. * There was much debate between internal, private, and public bug bounty programs. But it was agreed that if you do them, that you do them in that order. * There was another concern regarding the cost of a bug bounty program. Whether you do them or not, you're still going to pay for coding errors and vulnerabilities one way or another. It's either upfront or later. * Those new to bug bounty programs are not aware of the additional costs of management and engaging with the researchers and white hat hackers. That is a critical part of the bug bounty program. * Before you begin, set up a system to manage the flow of problems reported. If not, you and your staff could very quickly be overwhelmed. * Having a consistent and clear way you handle the findings is often more important than the findings. * Have you allocated budget to remediate the findings? Are you going to need to make cases as each weakness is found? * Keep in mind that companies don't go into bug bounty programs for the same reason. Some go into it for reasons of publicity or forming relationships with researchers. * Communications between your engineers and the bug bounty researchers is critical. If your team is non-responsive, the bug bounty program could backfire. * Most people are wary of public bug bounty programs because of the low signal-to-noise ratio. As there is a rush for attention and money, the whole effort may implode.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-data-classification/)

The more data we horde, the less useful any of it becomes, and the more risk we carry. If we got rid of data, we could reduce risk.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and guest Nina Wyatt, CISO, Sunflower Bank.

Thanks to this week's podcast sponsor, Cmd.

Cmd provides a lightweight platform for hardening production Linux. Small and large companies alike use Cmd to address auditing gaps, implement controls that keep DevOps safe, and trigger alerts on hard-to-find threats. With out-of-the-box policies that make setup easy, Cmd is leading the way in native protection of critical systems.

On this episode of Defense in Depth, you’ll learn: * Usable, user-friendly, viable-in-every-scenario data protection that is invisible, seamless, and always on does not exist, but could exist, and should exist. * Classification tools that tout automation, really aren't. There is still a good amount of manual intervention. * Another way to solve the data protection issue is to get rid of data. Our data protection problem amplifies as we find ourselves protecting more data. But a lot of data simply doesn't need to be protected. It could be classified for non-protection or just destroyed. * Data is mostly unstructured and it needs to be structured to the sense that you know how data is flowing, and that is extremely difficult to do. * We spend more time on hardware and networking diagrams but what we should be doing is diagramming data flow. * Mandate retention limits on data. People don't like it, but it's going to make you a lot safer. Just mandate the lifespan of data. If it's not needed or accessed in a certain period of time, archive it or possibly kill it. * People think holding onto data is costless, but reality is the more you hold onto it becomes very costly from a security perspective. * Utility to you vs. utility to the bad guys is relative. For example, a bank statement from five years ago has little utility to you now, but if a bad guy is looking for information, that has the same value as a bank statement from today. * The questions you need to be asking: Is your data sensitive, does it have open permissions, how long has it been since the data was accessed? * Data with PII is both an asset and a liability. * Classifying data also has a major problem with consistency. Often data can be put into multiple categories or classes. * Security of data is usually not the factor many consider. We are often thinking about the security around data.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-prevention-vs-detection-and-containment/)

We agree that preventing a cyber attack is better than detection and containment. Then why is the overwhelming majority of us doing detection and containment?

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and sponsored guest Steve Salinas (@so_cal_aggie), head of product marketing, Deep Instinct.

Thanks to this week's podcast sponsor, Deep Instinct.

Deep Instinct is changing cybersecurity by harnessing the power of Deep Learning to prevent threats in zero time. Deep Instinct’s on-device, solution protects against zero-day, APT, ransomware attacks, and against both known and unknown malware with unmatched accuracy and speed. Find out more about the solution’s wide covering platform play.

On this episode of Defense in Depth, you’ll learn: * A recent Ponemon study notes that most security professionals agree that prevention is a better security strategy than detection and containment. * Even with the acceptance that prevention is a better security posture, most security spending goes into detection and containment. * By implementing firewalls, patching, and security training, many of us are already doing prevention, but may not classify it as such. * Prevention is not nearly as expensive as creating a detect and respond security program. * The two halves work in concert together. No prevention program can be perfect, and that's why you always need a detect and contain program as well. * The reason you don't only go with detect and respond without prevention is that the flood of valid information will be too much for a security program to handle. * There was a strong argument for detect and respond because it shows the products you spent money on are actually working. This is not just to humor the security professional, but also to give some "evidence" to the senior executives. * A lot of prevention comes down to the individual. But since it's so tough to get people to change behavior, there's less friction to just purchase another prevention tool to protect people from their own behavior. * Prevention tools won't stop the attackers who sit dormant on a network waiting to attack. Their behavior has to be spotted with the use of detection and containment.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-asset-valuation/)

What's the value of your assets? Do you even understand what they are to you or to a criminal looking to steal them? Do those assets become more valuable once you understand the damage they can cause?

Check out this post for the basis for our conversation on this week’s episode which features me and Allan Alford. Our guest is Bobby Ford, global CISO, Unilever.

Thanks to this week's podcast sponsor, CyberArk.

At CyberArk, we believe that sharing insights and guidance across the CISO community will help strengthen security strategies and lead to better-protected organizations. CyberArk is committed to the continued exploration of topics that matter most to CISOs related to improving and integrating privileged access controls.

On this episode of Defense in Depth, you’ll learn: * Allan revised the well known formula for risk (Risk = Likelihood x Impact) to reflect an asset's importance. So instead, Risk = Threat plus Vulnerability as aimed at an Asset. * It's hard to get a stakeholder to tell you the value of their assets. Instead, ask them the reverse. Describe the absolute worst breach scenario. What's the second worse? And then on down until you have an understanding of the hierarchy of the assets. * A business impact analysis (BIA) will also help uncover asset valuation. Allan Alford has a BIA calculator on his site. * The simple question of "What are you defending?" is one that most business leaders struggle to answer. They need to be able to answer that question often. * Once you know what to defend the question is how much to defend and then after that is there anything that doesn't need to be defended. * You may actually not be able to start this process if you doing know what your asset inventory is. This should be managed with a discovery tool and multiple iterations of discovery. * While you're valuing your own assets, try to make sense of what these assets mean to an attacker. That will help you answer the question of "how much to defend".

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-devsecops/)

We know that security plays a role in DevOps, but we've been having a hard time inserting ourselves in the conversation and in the process. How can we get the two sides of developers and security to better understand and appreciate each other?

Check out this post and this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Allan Alford (@AllanAlfordinTX). Our sponsored guest is Sumedh Thakar (@sumedhthakar), president and chief product officer, Qualys.

Thanks to this week’s podcast sponsor, Qualys.

Qualys is a pioneer and leading provider of cloud-based security and compliance solutions.

On this episode of Defense in Depth, you’ll learn: * It's debatable whether the term "DevSecOps" should even exist as a term. The argument for the term is to just make sure that security is part of the discussion, but security people feel that's redundant. * Security is not an additional process. It should be baked in. It's an essential ingredient. * But should it really be seen as "embedding" or rather a partnership? Developers and operations operate as partners. * Instead of dumping security tools on developers and just demanding "implement this" security needs to go through the same transition development had to go through to be part of "Ops". * As DevOps looks forward to what's next, how can security do the same? * Security is unfortunately seen as an afterthought, and that's antithetical to the DevOps philosophy. * Security is an innate property that imbues quality in the entire DevOps effort. * Security will slow down DevOps. It's unavoidable. Not everything can be automated. But, if you deliver the security bite-sized chunks you can get to an acceptable level of speed. * Business needs to specify the security requirements since they were the ones who specified the speed requirements. That's how we got to DevOps in the first place.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-fix-security-problems-with-what-youve-got/)

Stop buying security products. You probably have enough. You're just not using them to their full potential. Dig into what you've got and build your security program.

Check out this post for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host Allan Alford (@allanalfordintx), and guest Brent Williams (@brentawilliams), CISO, SurveyMonkey.

Thanks to this week's podcast sponsor, Deep Instinct.

Deep Instinct is changing cybersecurity by harnessing the power of Deep Learning to prevent threats in zero time. Deep Instinct’s on-device, solution protects against zero-day, APT, ransomware attacks, and against both known and unknown malware with unmatched accuracy and speed. Find out more about the solution’s wide covering platform play.

On this episode of Defense in Depth, you’ll learn: * It's very possible you're not using the tools you've purchased to their full potential. What would happen if you completely stopped buying security products and tried to fix your problems with the tools you've already purchased? * The reason this is such a popular discussion is that as an industry we're still struggling with managing the fundamentals of security. * Shelfware happens because we buy before we're ready. Purchase decisions should be made in conjunction with knowing if you have the staff and understand the integration points to implement the solution. * Tooling for the few layers must be dealt with first. You don't need a solution selling a higher layer of security if you don't have the foundation built. * Much of this argument is based on the messaging we hear from vendors. They're understandably in the business of selling product. Be cognizant of how you're absorbing information. * We need to also focus on the people who unfortunately are fallible and can make non-malicious, but poor decisions. * If there was going to be any additional spending, the argument was to invest in your people - from the entire staff to specific training for your security staff.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-should-risk-lead-grc/)

Defining risk for the business. Is that where a governance, risk, and compliance effort should begin? How does risk inform the other two, or does calculating risk take too long that you can't start with it?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Allan Alford (@AllanAlfordinTX). Our guest is Marnie Wilking (@mhwilking), global head of security & technology risk management, Wayfair.

Thanks to this week’s podcast sponsor, Qualys.

Qualys is a pioneer and leading provider of cloud-based security and compliance solutions.

On this episode of Defense in Depth, you’ll learn: * The model of risk = likelihood x impact doesn't take into account the value of assets. Assets have to be valued first before you calculate risk. * Is the reason risk isn't used to lead governance, risk, and compliance (GRC) because it's so darn hard to calculate? Many CISOs say their toughest job starting out is trying to understand what the crown jewels are and what the board's risk tolerance is. * Risk management allows the board to know when you have enough security. Some assets may require eight layers where others may only require one or two. * Determining likelihood of an attack involves a good amount of guesswork. We've discussed on a previous episode of CISO/Security Vendor Relationship Podcastthat we don't go back to see how good our risk predictions were. If you want to get better at it, you should. Otherwise, it will always be guesswork. * Even if you can get someone to agree what their risk tolerance is, or what asset is of importance, trying to get agreement among a group can be a blocker. Keep in mind that each person is going to have a different viewpoint and concerns. * Knowing risk appetite is critical. You can apply security controls without knowing it, but that's providing a unified security layer across all data, people, and applications when they are all not equal when it comes to asset valuation.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-responsible-disclosure/)

Security researchers and hackers find vulnerabilities. What's their responsibility in disclosure? What about the vendors when they hear the vulnerabilities? And do journalists have to adhere to the same timelines?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series and Allan Alford (@AllanAlfordinTX). Our guest is Tom Merritt (@acedtect), host, Daily Tech News Show.

Thanks to this week’s podcast sponsor, Qualys.

Qualys is a pioneer and leading provider of cloud-based security and compliance solutions.

On this episode of Defense in Depth, you’ll learn: * Manufacturers, software companies, researchers, hackers, and journalists all play a role in responsible disclosure. * Vulnerabilities will exist, they will be found, and how companies want to be alerted about those issues and inform their public are key elements in the process of responsible disclosure. * While there are CERT guidelines for responsible disclosure, there are no real hard and fast rules. There will always be judgement calls involved. But like the doctor's Hippocratic Oath, the goal is to minimize harm. * You can't announce a vulnerability without offering a fix. It's opening the door to the bad guys to come in and cause havoc. * There is a long history of how vulnerabilities have been disclosed. It often was a surprise and malicious. The trend of responsible disclosure and bug bounties has given rise to the legitimacy of white hat hackers and the process of exposing vulnerabilities. * One listener argued that the term "responsible disclosure" implies a moral judgement. He argued that it should be referred to as "coordinated disclosure." * There is still frustration on multiple sides with how responsible disclosure should be handled. Researchers sometimes argue they're not getting recognized or paid. Companies often feel extorted by researchers who want answers on their timelines. And journalists have to weigh the importance and criticality of a vulnerability. Should they let people know about it even if there really isn't a good fix yet.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth:-internet-of-things/)

When Internet of Things or IoT devices first came onto the market, security wasn't even a thought, let alone an afterthought. Now we're flooded with devices with no security and their openness and connectivity are being used to launch malicious attacks. What are methods to secure environments today and how should these IoT devices being secured in the future?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series and Allan Alford (@AllanAlfordinTX). Our guest is Josh Corman (@joshcorman), founder of I Am The Cavalry.

Thanks to this week’s podcast sponsor, Pulse Secure.

Pulse Secure offers easy, comprehensive solutions that provide visibility and seamless, protected connectivity for hybrid IT in a Zero Trust world. Over 20,000 enterprises entrust Pulse Secure to empower their mobile workforce to securely access applications and information in the data center and cloud while ensuring business compliance.

On this episode of Defense in Depth, you’ll learn: * For years, manufacturers didn't consider device security. As a result, attackers have used insecure devices like connected webcams to gain entry into a corporate network. * If you're manufacturing devices, then make security and patches a top concern even after end of life support. * Big gap between public trust and the reality. Almost all people trust manufacturers to secure their devices. The reality is most manufacturers aren't securing their devices. * While we've seen webcams used to launch distributed denial of service (DDoS) attacks, the greatest concern is of a similar style attack being launched against industrial IoT. * The discussion of IoT security goes beyond security of devices. We know there are devices with zero security connected to our network. This is where a larger discussion of zero trust and defense in depth style security programming comes into play. * We have a growing number of unmanaged devices. Devices that are just always on and connected to the Internet providing simple functions like reading their environment. * How much responsibility do manufacturers have for the security of their devices after they've been purchased and shipped? They can create updates and patches, but they can't enforce them.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-is-governance-the-most-important-part-of-grc)

Your policy should rarely change. But your ability to achieve that policy is found in procedures or governance that should inform, steer, and guide your team. Those procedures should change often and others should follow. Are they?

Check out this post for the basis for our conversation on this week’s episode which features me and Allan Alford. Our guest is Mustapha Kebbeh (@mustaphake), CISO, Brinks.

Thanks to this week's podcast sponsor, CyberArk.

At CyberArk, we believe that sharing insights and guidance across the CISO community will help strengthen security strategies and lead to better-protected organizations. CyberArk is committed to the continued exploration of topics that matter most to CISOs related to improving and integrating privileged access controls.

On this episode of Defense in Depth, you’ll learn: * By leading with governance, how do you make a governance, risk, and compliance (GRC) program meaningful? * Without the right governance it will be hard to accomplish the bigger picture. * GRC requirements have to adhere to the three A's: actionable, accountable, and achievable. * GRC programs require strong leaders. Without them, nobody will follow a governance effort. * There was debate on whether risk or governance should lead the GRC effort. But everyone appeared to agree that leading with compliance is very dangerous. * A list of rules, or governance, is completely pointless if it's not enforced. Enter risk, compliance, and a good leader and you've got the opportunity for enforcement. * Governance that's not tied to risk will probably be ignored and therefore useless. * The argument to lead with risk is because it has applicability to the business where it's questionable with governance and compliance. But for the purpose of this episode's argument, we were making a case for governance leading the conversation. * The main argument for governance over risk is that you can't truly understand the risk if there isn't some type of structure to understand what you're dealing with.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-who-should-the-ciso-report-to/)

Who should the CISO report to? What factors determine that decision? And why is that single decision so critical to a company's overall security?

Check out this post for the basis for our conversation on this week’s episode which features me, special guest co-host Yaron Levi (@0xL3v1) CISO, Blue Cross Blue Shield of Kansas City. Our guest is Gary Harbison, vp, global CISO, Bayer.

Thanks to this week's podcast sponsor, IBM Security.

IBM Security offers one of the most advanced and integrated portfolios of enterprise security products and services. The portfolio, supported by world-renowned IBM X-Force research, provides security solutions to help organizations stop threats, prove compliance, and grow securely. IBM operates one of the broadest and deepest security research, development and delivery organizations. It monitors more than two trillion events per month in more than 130 countries and holds more than 3,000 security patents.

On this episode of Defense in Depth, you’ll learn: * We're having this discussion because as Allison Berey, M:CALIBRATE explained, "Wrong reporting lines can mean poor decision-making." * There is no definitive answers as to what the reporting line should be. The final answer on this this discussion was "it depends." * A CISO's placement within an organization should depend on where a company derives its value. * All companies say security is important. How they place the CISO within the reporting structure and the influence they have on the organization is very telling as to whether the company truly does value security. * There was a lot of concern reporting to other C-level executives that are not the CEO as the CISO's concerns could play second fiddle to a CFO, CIO, or CRO's primary desires. * Many felt the most desirable reporting line was CISO-to-CEO. * But, assuming every department is dealing with some sort of business risk, don't they all have the right to report to the CISO? Where do you draw the line?

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-hybrid-cloud/)

The consistency of your security program becomes a challenge once you introduce the cloud. Controls and visibility are not necessarily transferable. How do you maintain the control you want in a hybrid environment?

Check out this post for the basis for our conversation on this week’s episode which features me, special guest co-host Taylor Lehmann (@BostonCyberGuy), vp, CISO, athenahealth, and our sponsored guest, Chris Meenan (@chris_meenan), director, offering management and strategy, IBM Security.

Chris Meenan, director, offering management and strategy, IBM Security, David Spark, producer, CISO Series, Taylor Lehmann, vp, CISO, athenahealth.

Thanks to this week's podcast sponsor, IBM Security.

IBM Security offers one of the most advanced and integrated portfolios of enterprise security products and services. The portfolio, supported by world-renowned IBM X-Force research, provides security solutions to help organizations stop threats, prove compliance, and grow securely. IBM operates one of the broadest and deepest security research, development and delivery organizations. It monitors more than two trillion events per month in more than 130 countries and holds more than 3,000 security patents.

On this episode of Defense in Depth, you’ll learn: * Moving to the cloud, like any other technology initiative, is a business decision. * What controls are you ceding over to the cloud provider? What service level agreements (SLAs) and performance measurements do you have for the provider? * Be realistic about what’s going to be done if a service provider violates the SLA. You’re not going to all of a sudden dump the provider. You’re going to put some types of corrections in place. Make sure you know what those are and how that can be handled, realistically. * Understand your shared responsibility in the cloud. According to a report by FireMon on hybrid cloud use and adoption, about one-third do not fully understand the shared responsibility model of the cloud. * Start slow. While you may need to go with multiple cloud providers to fill distribution and requirements, begin with one and learn from that experience. * Use cloud adoption as an excuse to join forces with your privacy team to understand where data is being placed and what control you have over it. * Cloud providers are not interchangeable like a utility. Cloud providers are chosen based on the services they offer.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-ciso-tenure/)

The CISO has the shortest tenure of any C-level role. Why so brief? Is it the pressure, the responsibility, the opportunities, or all of the above?

Check out this LinkedIn discussion to read the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), producer of CISO Series and guest co-host Gary Hayslip (@ghayslip), CISO, Softbank Investment Advisers. Our guest is John Meakin, CISO, Equiniti.

Thanks to this week's podcast sponsor, IBM Security.

IBM Security offers one of the most advanced and integrated portfolios of enterprise security products and services. The portfolio, supported by world-renowned IBM X-Force research, provides security solutions to help organizations stop threats, prove compliance, and grow securely. IBM operates one of the broadest and deepest security research, development and delivery organizations. It monitors more than two trillion events per month in more than 130 countries and holds more than 3,000 security patents.

On this episode of Defense in Depth, you’ll learn: * There's a lot of confusion as to what a CISO needs to do. All job descriptions for CISOs are different. * There are humans behind the data and as a result CISOs are tasked with protecting the humans. * CISOs can improve their tenure if they seek out a business mentor to allow them to better support the business. * CISOs who aren't able to communicate clearly will not last long. * It's a CISO's job to communicate in the language of the business, not the other way around. * Before the CISO ever arrives, there's a business culture. There's always going to be a natural push back from the business. "Why are you making us change?" * A simple walkabout the office can solve a lot of uncertainty. * If employees start asking questions about their personal security, that's a good sign the CISO has successfully inserted security into the business culture. * Another huge factor that impacts CISO tenure are the increased opportunities. Regulations and privacy laws are pushing companies to get CISOs to provide much needed oversight. * What does the reporting structure in your organization mean in regards to the CISO being heard at the executive and board level?

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-toxic-security-teams/)

There's an endless number of variables that contribute to creating a toxic security teams. How does it happen, and what are ways to manage and eradicate the toxicity?

Check out this LinkedIn discussion to read the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), producer of CISO Series and Allan Alford (@AllanAlfordinTX). Our guest is Jinan Budge (@jinan_forrester), principal analyst serving security & risk professionals at Forrester.

On this episode of Defense in Depth, you’ll learn: * Toxic security teams happen because of tribalism, not just within security, but across all departments. * Security is seen as an expense and an IT problem and many don't think it's everyone's issue. * One core issue is the lack of security culture and management simply not supporting the InfoSec team's efforts. * There are many ways a security team's culture can become toxic. The issues are so numerous that it seems more of a challenge to prevent a team from its natural tendency to go sideways. * The hero mentality of one individual, who thinks only he/she can solve the problem, can poison an entire group. * It can be argued that it's an issue of ego, but many see it as insecurity. Often the individual needs to prove to themselves and others in order to maintain their cybersecurity rockstar status. * A toxic security team will have a very hard time hiring new staff. People will leave and tell others you don't want to work there. * If you have a diverse team and there's toxicity, the team won't last. * There's an enormous cost to disengaged employees.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-personality-tests-in-the-workplace/)

As a cybersecurity leader, should you use personality tests for hiring and managing a team? Does it create diversity, understanding of communication styles, or does it just create more conflict?

Check out this LinkedIn discussion to read the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), producer of CISO Series and Allan Alford (@AllanAlfordinTX). Our guest is Ursula Alford, psychologist, Department of Neuropsychology, Baylor Scott & White Institute of Rehabilitation.

On this episode of Defense in Depth, you’ll learn: * There is plenty of debate as to whether a security leader should use personality tests, such as Myers-Briggs, for hiring or managing employees. * Almost universally, no one wanted to use the tests for hiring as it creates bias, but many saw value in using them for managing employees. * About half of the people who participated in the discussion just wanted to steer clear of personality tests altogether, never wanting to force their employees to take them either. * The tests reveal individuals' preferred communication styles which can be helpful for customizing employee management. This is the main reason they're used. * Don't mistake these tests as defining who you are in the future. It's a test to measure personality and communications in a moment in time. People are often asked to take these tests repeatedly and we often score differently with our personalities changing. Meyers-Briggs definitely has issues with validity and reliability. * One significant value to any personality test is to see if you're getting a variety of thought patterns on your team. If you're not, then you may be building the wrong team.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-lack-of-diversity-in-cybersecurity/)

Cybersecurity teams are notoriously not diverse. At the same time we keep hearing and talking about the need for diversity. Is it critical? Can you be just as successful without it?

Check out this Twitter feed for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series and Allan Alford (@AllanAlfordinTX). Our guest is Christopher Zell, vp, head of information security, The Wendy's Company.

Thanks to this week's sponsor, Electronic Frontier Foundation.

On this episode of Defense in Depth, you’ll learn: * Discussion is based on a quote by one PayPal co-founder, Max Levchin, who said, "The notion that diversity in an early team is important or good is completely wrong. You should try to make the early team as non-diverse as possible." * There is diversity of people and there's diversity of opinions. Those two often go together, but they don't have to. * While appalling, there is some truth to Levchin's statement. When everyone thinks the same you don't have conflict and can move quickly. * But lack of diversity of opinion means you don't see the full picture and that can make you susceptible to unforeseen vulnerabilities. * If you don't know what problems you're facing, you should want diversity. * Minorities often face different and more struggles than those who never have to suffer diversity issues. They've been hardened and that should make them an even more attractive candidate. * Start building your diverse network now. When it comes time to hire diversity and you don't have that network already in place, you're going to have a very difficult time. * For more, check out the (ISC)^2 study "Innovation Through Inclusion: The Multicultural Cybersecurity Workforce" and Computerworld article, "The next tech skillset is ‘differently-abled neuro-diverse’".

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-when-are-cisos-responsible-for-breaches/)

When is a CISO responsible for a breach or cyber incident? Should they be disciplined, fired, or let go with an attractive payout?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series and Allan Alford (@AllanAlfordinTX). Our guest is Norman Hunt (@normanhunt3), deputy CISO, GEICO.

On this episode of Defense in Depth, you’ll learn: * On the onset, one may want to jump to finding liability. But a CISO's responsibility should not be isolated at the moment of the breach. There are more issues to consider, such as authority, accountability, efficacy, and expectations. * Be wary of assigning accountability if the CISO didn't have the authority to actually carry out his/her intended plan. * Often the CISO is seen as a necessary scapegoat when there is a breach. It shows an aggressive move by the company to make a change, but then they'll have to go ahead and hire another CISO, probably at a much higher salary (see last week's episode). * When are you measuring the performance of the CISO? Is it as they build the security program, or is it only at the moment of the breach? * How well does a CISO handle the breach when it happens and how well do his direct reports and the rest of the company handle it? That's a better measurement of the efficacy of the CISO. * CISOs are held to a higher level of expectation to prevent a risky event from happening. CIOs, CEO, and CFOs are not held to the same standard. * Even the best CISOs will suffer a breach. It's a single point in time. It sure is a very bad point in time, but what are the events that led up to this moment. Were they building out a security program and were there improvements or was staff education and leadership falling short? * The best standard of measurement of a CISO is how well do they communicate and implement security and risk decisions? * Failure may be at the definition of the role of the CISO. A CISO's role and its responsibilities are far from standardized.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-post-breach-desperation-and-salary-negotiations/)

A data breach usually spells financial and reputational disaster. But such an event can also be an opportunity for a security professional to capitalize.

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series and Allan Alford (@AllanAlfordinTX). Our guest is Michael Piacente, co-founder and managing partner, Hitch Partners.

Thanks to this week’s podcast sponsor, Anomali.

Anomali is a leader in intelligence-driven cybersecurity solutions. Anomali turns threat data into actionable intelligence that drives effective security and risk decision making. Customers using Anomali identify cyber threats from all layers of the web, automate blocking across their security infrastructures, and detect and remediate any threats present in their networks. www.anomali.com

On this episode of Defense in Depth, you’ll learn:

  • Salary negotiation is a topic that is always in vogue, but the post-breach angle shows the value companies are eventually seeing in the CISO role. Unfortunately for them they realize it after the fact.
  • A bad breach incident will cost far more than an investment in a good security team. But that's your insurance policy.
  • Location, industry, and size of company are all key factors on whether or not a CISO will be able to command a seven figure salary.
  • Industry specific skills will definitely come into play. If a bank is breached and you've been a security professional or a CISO at multiple banks that has maintained its cybersecurity without any significant incidents, then you have a lot of leverage.
  • When a company needs a CISO to right the ship, they're going to want someone who has gained skills in the areas of communicating with the board, strategy, vision, leadership, and successfully creating a pro-security culture.
  • Negotiating salary is not just isolated to CISO role. There are cloud security architects that are in high demand and can garner a much higher wage than just a couple years ago.
  • Threats outnumber security people regardless of their rank. There's no one person that's going to prevent breaches. But if you have a poor security culture, then a company will need to pay for the talent to get it operating in the right direction.

View Details

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-presenting-to-the-board/)

What metrics, reports, or strategies should a security professional utilize to communicate the value to the board? Or is the mode of "presenting to the board" a damaged approach?

Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series and Allan Alford (@AllanAlfordinTX). Our guest is Barry Caplin (@bcaplin), executive leadership partner, Gartner.

Thanks to this week’s podcast sponsor, Anomali.

Anomali is a leader in intelligence-driven cybersecurity solutions. Anomali turns threat data into actionable intelligence that drives effective security and risk decision making. Customers using Anomali identify cyber threats from all layers of the web, automate blocking across their security infrastructures, and detect and remediate any threats present in their networks. www.anomali.com

On this episode of Defense in Depth, you’ll learn: * A conversation with the board begins with a discussion of what risk is. But getting that information out of the board is far from a simple task. Vague answers are not helpful. * Metrics are of value to the board, but avoid offering up tactical metrics. Instead, utilize strategic metrics. * Once risk appetite is understood and agreed upon, then it's appropriate to begin a discussion of the security program's maturity. * Caplin recommends a four-slide presentation for the board: 1. Where we were, problem areas identified per risk and maturity. 2. What we spent and a bit of why we spent. 3. Where we are now (metrics come into play here). Best to show how much progress you've made in implementing security programs. 4. Where we want to go next, and what the next ask is. * If you're going to show a metric, it should answer a very specific question for the board. * If you are going to show one metric, the most popular one is dwell time or the time between when an attack happens, when you discover it, and when it's remediated. * The one metric of dwell time provides a lot of information as to the maturity of a CISO's security program as it coincides with its ability to respond to incidents. * Some CISOs aim for a storytelling approach completely avoiding metrics because metrics have unfortunately led the board down the wrong path. It's either the wrong metrics, too detailed of a metric, or metrics not tied to business risk or to a maturity model.