The CISO's Gambit podcast is a pragmatic cyber risk dialogue between cyber security leaders from leading organizations, like Zscaler. Topics span technical and non-technical aspects of cyber risk, cybersecurity, privacy, transformational change management, and the evolving role of the CISO as a thought leader and change agent. The podcast covers current risks, what's on horizon, and how CISOs can help deliver business value that lowers risks, flattens the total cost of controls, and reduces security friction on user experience and business velocity. You can subscribe to the podcast feed on Apple Podcasts and Spotify.
Shannon Lietz is an award-winning security professional, patent-holder, visionary innovator, and industry leader. She joins host Sean Cordero for an in-depth discussion on lucky vs. good cybersecurity, passion-based hiring, DevSecOps, and our industry’s need for accountability and metrics.
Jack Leidecker oversees the security of an AI-driven revenue platform that derives advanced revenue and sales insights. Hear his insider’s view on AI’s current trajectory and the importance of remembering one’s roots in a high-tech world.
Lance Dubsky talks about securing everything from orbital technology to the ocean floor in his compelling description of the ambitious goals of Quintillion Subsea Operations.
In a first, host Sean Cordero welcomes accomplished venture capitalist to the show, Marcus Bartram, General Partner at Telstra Ventures. Marcus has backed investments in such recognizable security ventures as CrowdStrike (a Zscaler partner). Throughout their conversation, Bartram explains what he looks for in an attractive cybersecurity investment, what startups look for in CISO and external advisors, and how to scale great ideas into a successful business.
Not everyone arrives at work in the morning to advance humans’ understanding of our place in the universe. But David Liska does. As the Associate Director of Engineering & Technology at the Space Telescope Science Institute, he’s been integral in launching and operating one of humanity’s most ambitious astronomical projects to date: the James Webb Telescope. In this episode, learn what it takes to manage such a massively complex undertaking, Liska’s lessons for working on public sector projects, and what about the universe still fills him with wonder.
Does academia take the right approach to producing tomorrow's cybersecurity leaders? What role should private sector leaders play? JP Saini, Chief Digital & Technology Officer at Sunbelt Rentals joins host Sean Cordero to discuss how mentorship directly contributes to better business outcomes, the importance of soft skills, and the fundamentals necessary to find success in a cybersecurity career.
Get up to speed on the art and science of training models, big data sets, and limitations and possibilities for AI in cybersecurity and beyond. Zscaler Vice President of AI and Machine Learning Howie Xu has been a pioneer in applying AI and ML to cybersecurity since the late 1990s. In this episode, he is joined by VP and CISO AMS - Brad Moldenhauer, and host Sean Cordero to discuss the state of applied ML and AI and the future.
After the RSA showroom floor proved zero trust's popularity as a buzzword, how will its tenants be solidified and standardized to separate true adherents from charlatans? To find out, host Sean Cordero welcomes John Yeoh, global vice president of research at the Cloud Security Alliance, and Lauren Wise, senior director, global executive advisory at Zscaler to discuss the recently announced Zero Trust Advancement Center and its mission to become the vendor-agnostic industry "North Star" for the strategies and solutions that make up zero trust cybersecurity.
Zscaler VP & CISO Brad Moldenhauer joins host Sean Cordero for a deep dive into new phishing data and tactical analysis provided by the Zscaler ThreatLabz team. They cover why political turmoil tends to correlate with rising phishing rates, phishing attack vectors like browser-in-the-browser (BitB) that are gaining steam among adversaries, supply chain risk, and why spear phishing is still a whale of a problem. Listen now to learn more about the latest developments in phishing tactics.
There is no one path to the top security role, but once there, the challenges for newbie CIOS are familiar. What are the keys to success? What kind of background and skill set is best? How do you pick up an inherited tech stack and budget and run with it? What is the right organizational structure given how infrastructure and risk management have evolved? To answer these top questions and more, host Sean Cordero, Zscaler CISO - Americas goes deep with Heng Mok, Zscaler CISO - APJ, a relative newcomer to the team with a prolific career journey.
The global M&A market is on a record-setting pace with trillions of dollars in transactions every year. With that comes a lot of success stories and unfortunate failures. In this episode, CISO-Americas and host Sean Cordero and Zscaler guests Sami Ramachandran, Managing Director, M&A, Divestiture, Private Equity, and Pam Kubiatowski, Field CTO, detail how the strategic use of cybersecurity and networking can be the linchpin for successful and rapid IT integration and separation for mergers, acquisitions, and divestitures.
Sean welcomes Bryan Green, former Business Information Security Officer (BISO) at Salesforce, and Brad Moldenhauer, former CISO at Steptoe & Johnson, as guests in this stage-setting discussion into trends and concerns that will occupy the minds and focus of cybersecurity leaders the world over. Listen for perspectives and insights you can use in your planning and strategies for ransomware, cryptocurrencies, cyber-insurance, and critical infrastructure.
CISO - Americas, Sean Cordero, a newcomer to the Zscaler team, picks up the reins as host and interviews Deepen Desai, the Global CISO and Head of Security Research at the company about the most pressing cybersecurity topic this month, Log4j. Listen in for insights into how attackers can and have been exploiting the massive vulnerability, prevention measures, and if we’re headed toward a world where every day seems like Patch Tuesday.
The Zscaler CISO team is joined by their esteemed colleague, Sahir Hidayatullah, to investigate the capability known in the cybersecurity industry as Active Defense.
The Zscaler CISO team has been actively engaged with customers on various threat prevention and detection strategies for SecOps maturity. The problem in this area today is apparent: alert fatigue, false positives, data paralysis, complexity, ineffectiveness. This suggests transformational change is required to protect against the threatscape that continues to expand the sophistication of its arsenal. Enter Active Defense (aka Adversary Engagement) and its human threat focus, to proactively combat the threat through engagement, disruption, and asymmetry. The Zscaler CISO team is joined by one of the pioneers in the Active Defense space, Sahir Hidayatullah, to investigate this capability and how he sees this capability working in a zero-trust environment. Discussion topics include:
CISA TIC Program Manager, Sean Connelly, speaks with our Federal CISO, Danny Connelly, about the game changing aspects of TIC 3.0 and what it means for the federal government.
The Office of Management and Budget (OMB) Memorandum M-19-26, “Update to the Trusted Internet Connection (TIC) Initiative”, provides agencies a modernized approach to implement the TIC initiative (TIC 3.0).
The initial implementation of Trusted Internet Connections (TIC), as mandated by OMB in 2007 required agencies to consolidate external connections and deploy common tools to enhance network security across the Federal Government. This required “agency traffic to flow through a physical TIC access point, which has proven to be an obstacle to the adoption of cloud-based infrastructure.”
On this episode of the CISOs Gambit, Zscaler Federal CISO, Danny Connelly speaks with Sean Connelly, CISA TIC Program Manager about TIC 3.0 and the game changing aspects that enable federal agencies to move away from legacy network security solutions and modernize cybersecurity.
The Zscaler CISO team has been hearing the same question in their day-to-day interactions: should I deploy zero trust: at the edge or at the endpoint? In this podcast, they share their perspectives on why a layered defense is critically important to protect organizations from today's threats. SASE + EDR = “Better Together”, and the team clears up some uncertainties about things like:
The Zscaler CISO team looks at the inherent tension between business enablement and cyber security that plays out in many organizations. How do you balance the need for strong security AND still adopt cloud-and mobile-technologies that allow for business agility, resiliency, and user productivity?
The Zscaler CISO team delves into what happened at Colonial Pipeline, and the federal government’s response to the attack in the form of the Executive Order on Improving the Nation’s Cybersecurity.
The Zscaler CISO team looks at the 25-year-old technology of Virtual Private Networks (VPN), and recent VPN vulnerabilities that have hit the news. In this episode, they cover:
The Cloud Act is a 2018 set of regulations that impact enterprise and network security. How is it important to CISOs, enterprises, and organizational security? The team looks at:
In this episode, Brad Moldenhauer, Marc Leuck, Nicolas Casimir, and Danny Connelly of the Zscaler CISO team cover the ins and outs of SSL inspection for enterprise cybersecurity posture. They review:
The COVID-19 crisis was a massive shift for how enterprises looked at security, and more importantly, acceptance of risk. Brad and Danny discuss how the change impacted: