JC Gaillard and his guests share their views on both the interesting cybersecurity news stories of the week and their own experiences. Now entering its third series with a stronger focus on cyber security governance and related board-level matters
Selected by Feedspot in their 2022 list of the Best 80 Cyber Security Podcasts
Please feel free to reach out to find out more
Jean Christophe Gaillard M: +44 (0)7733 001 530 E: jcgaillard@corixpartners.com https://twitter.com/Corix_JC https://twitter.com/CorixPartners https://twitter.com/TCyberCast
In this episode, JC Gaillard looks back at the various messages at the heart of the storytelling of security vendors, and highlights why true independence is a rare but essential commodity in the cybersecurity world; read his original article on the theme here
In this episode, JC Gaillard goes back to the dynamics surrounding the procurement of cybersecurity tools and explains why cybersecurity transformation is not - and cannot be - about implementing yet another technology product; read his original article on the theme here
In this episode, JC Gaillard shares his - still evolving - views on the impact Generative AI can have on cybersecurity and reflects on how the situation have evolved (or not) since his first article on the theme back in 2018
In this episode, JC Gaillard goes back to the topic of security tools proliferation discussed in previous series and highlights why it should be central to the role of the CISO to build a vision and a product strategy, and drive the decluttering of cybersecurity landscapes
In this episode, JC Gaillard looks back at the role of the CISO, how it has evolved over the past two decades and where the priorities should be to drive real and lasting transformation around cybersecurity; read his interview on the theme here
In this episode, JC Gaillard looks back a the cybersecurity toolkit landscape and the issues already highlighted in earlier series of the podcast and put things in perspective around the need to declutter; read his interview on the theme here
In this episode, JC Gaillard explores the relationship between cybersecurity vendors and Board oversight, why they appear to be so driven by it and where their arguments often appear to be flawed
In this episode, JC Gaillard looks back at a number of cybersecurity governance aspects he has written or spoken over the past few months, in the light of a recent report by Diligent and Bitsight
In this episode, JC Gaillard makes a rare foray in the field of Artificial Intelligence and generative AI and highlights what he sees as the big untold problem at the heart of many discussions on the theme
In this episode, JC Gaillard talks around the concept of risk and the importance of using accurate and rigourous language around those aspects across the cybersecurity industry; read more about the approach he highlights in this whitepaper
In this episode, JC Gaillard looks back at the role of the virtual CISO and in particular why many small firms would often benefit from looking internally first, before jumping to externalised cybersecurity solutions; read his original article on the theme here
In this episode, JC Gaillard continues his journey across cybersecurity governance matters, and in particular he goes back to the construction of the role of the CISO and why it is essential to put it back in its historical perspective; read his original article on the theme here
In this episode, JC Gaillard continues to explore cybersecurity governance and in particular, why it is essential to place it in a broader corporate governance context; read his original article on the theme here
In this first episode of the series, JC Gaillard explores issues around cybersecurity governance and ownership and in particular, why cyber resilience needs clear accountability from the top; read his original article on the theme here
The UK Government "call for views" around a proposed "Cyber Governance Code of Practice" mentioned in the episode can be found here
In this final episode of Series 4, JC Gaillard goes back to the role of the Board in relation to cybersecurity and clarifies a number of aspects from earlier episodes; read his original article on the theme here
As we reach that time in the journalistic calendar where predictions for the year to come start to appear, JC Gaillard reflects on what it means for the cybersecurity industry and the real cycles over which it has been evolving
In this episode, JC Gaillard explores the meaning of cyber resilience across the industry, why some many people use the term to mean so many different things and what can be done to harmonise the approach to the concept; read his original (2019) article on the theme here
In this episode, JC Gaillard goes back to the discussions in Episode 14 and 16 and continues to analyse the comments received in response to his earlier article around the failed role of the CISO; in this episode, more on the role of the Board and why it needs to own cybersecurity in business terms, not in technology terms.
In this episode, JC Gaillard starts to explore the nature and the mechanics of the relationship between the CISO and the Board, in the light of two recent surveys and their conflicting headlines; References: The ComputerWeekly article mentioned in the episode can be found here; The InfoSecurityMag article can be found here; and the Proofpoint report "Cybersecurity: The 2023 Board Perspective" here
In this episode, JC Gaillard looks back at what has been happening in some large organisations around cybersecurity across the last two decades, and at the dynamics of what he has been calling the "cybersecurity spiral of failure"; read his original article on the theme here
In this episode, JC Gaillard looks back at the role of the CISO in the light of discussions on the theme in the last few episodes, and takes a recruitment perspective on the role, its history and its evolution with guest and recruitmemnt specialist Owanate Bestman; some of JC's views on the topic can be found here; Owanate's profile can be found here
In this episode, JC Gaillard and guest Mark Segelov look back at the reporting line of the CISO, and why it is still a hot topic of discussion amongst cybersecurity professionals; JC's views on the topic can be found in those 2 pieces from 2017 and 2018, which are revisited in the podcast; Mark's Linkedin profile can be found here
In this episode, JC Gaillard goes back to the content of Episode 14 and explores a number of comments received on Linkedin around the associated article, and in particular, how the role of the CSO needs to be conceived and positioned, and the importance of a structured cybersecurity operating model
In this episode, JC Gaillard looks back at IT GRC programmes, why they often fail, and why integration of business threats, technology risks, controls and protective measures is key to success; read his original article on the theme here.
In this episode, JC Gaillard revisits earlier discussions around the role of the CISO, highlighting issues with the historical construction of the role and why a CSO role may be the way forward in some firms; read his original article on the theme here
In this episode, JC Gaillard and Richard Preece continue their exchanges initiated in Episode 6 of this series around supply chain risk and comment on the outcome of the Security Transformation Research Foundation meeting in late June
In this episode, JC Gaillard revisits two apparently conflicting vendor surveys and explores how playing the cybersecurity numbers game can leave CISOs weakened and exposed; read his original article on the theme here
In this episode, JC Gaillard looks at the challenges involved with cybersecurity benchmarking, and why the CISOs need to be careful when answering what could be a politically loaded question
In this episode, JC Gaillard explores the momentum behind the role of the Chief Security Officer and why it starts to make sense in many firms to evolve the role of the CISO and return it to its native technical content
In this episode, JC Gaillard explores the dynamics of change around cybersecurity in the light of this article from the Harvard Business Review, and highlights two essential steps for success; read his original article on the theme here
In this episode, JC Gaillard looks back at a recent survey from IANS Research and questions whether you should really expect your current CISO to sit on the Board; read his original article on the theme here
In this episode, JC Gaillard addresses the challenges of cybersecurity for small and mid-size businesses and in particular how a number of misconceptions still lead to the adverse prioritisation of security matters and protective measures; read his original article on the theme here
In this episode, JC Gaillard and guest Richard Preece start exploring the various dimensions involved in managing supply chain risk, what it means for businesses, and how it differs from traditional vendor risk.
In this episode, JC Gaillard looks back at the state of the cybersecurity industry and analyzes possible reasons behind the proliferation of security tools and services, and the problems it creates for large organizations; read his original article on the theme here
In this episode, JC Gaillard goes back to the "when-not-if" paradigm around cyber attacks, which he mentioned in previous episodes, and explores its impact for the CISO; read his original article on the theme here
In this third episode of our fourth series, JC Gaillard looks back at cybersecurity budgets and analyzes the reasons behind the considerable underspent highlighted by a recent survey; read his original article on the theme here
JC Gaillard looks back at a number of aspects involving zero-trust technology and why putting technology first is probably the biggest mistake you can make in that space; read his original article on the theme here
Welcome to the 1st episode of our 4th Series - JC Gaillard starts to look back at the various topics that have been catching his eye since the end of the previous series: In this episode, why it is key to look beyond the hype on a number of tech matters and refocus our approach to cyber security on key concepts; read his original article on the theme here
JC Gaillard reaches the final episode in this third series of the Corix Partners Cyber Security Transformation Podcast, and revisits a few key aspects highlighted throughout the series, in particular the importance of the "Process and People first, then Technology" principle
JC Gaillard continues to analyze the way the various aspects highlighted in earlier episodes of the Series are interlinked; in this episode, he goes back to the "when-not-if" paradigm around cyber attacks and why tactical and strategic execution is paramount for the new CISO
JC Gaillard reaches the final episodes in this Series and starts to look at how the various aspects highlighted in earlier episodes are interlinked; in this episode, the key traits senior execs and Board members need to focus on when hiring a new CISO
JC Gaillard looks at the way the cyber security agenda needs to be framed at Board level, to enable the best positioning of the role and profile of the new CISO ahead of the "First 100 Days"
JC Gaillard digs into the concept and definition of a Security Operating Model, why it needs to underpin the "First 100 Days of the New CISO", and why "Process and People first, then Technology" has to be the main guiding principle here
JC Gaillard continues exploring a few specific topics surrounding the "First 100 Days of the New CISO"; in this episode, the reporting line of the CISO, why it matters and how to determine which would work best
As part of his continuing exploration of the "First 100 Days of the New CISO", JC Gaillard looks into the profile of the CISO and why management experience is of paramount importance, over and above technical knowledge.
JC Gaillard continues exploring the topics surrounding the "First 100 Days of the New CISO"; in this episode, he dives into the aspects surrounding the tenure of the CISO and why it is key to driving security transformation
JC Gaillard is joined by Head of Cyber and Information Security at Swansea University Neil Cordell, to discuss his real-life experience of taking up a new CISO position in the midst of the Covid pandemic, and the lessons that can be learnt about bringing all stakeholders on board the cyber security transformation journey
Neil's details can be found here on Linkedin >> https://www.linkedin.com/in/neilcordell/
JC Gaillard reaches the end of his exploration of the "First 100 Days of the New CISO" and before moving on to a number of episodes with guests on the theme, he digs into "expectations vs. reality" and explores the root causes of the disconnect which may exist between what the CISO finds on arrival and what they were sold at interview time
JC Gaillard continues its exploration of the "First 100 Days of the New CISO" with an analysis on how tactical firefighting and the unavoidable handling of cybersecurity incidents must not be seen just as a "curse" throughout the first 100 days, but can be used to build up trust with stakeholders
JC Gaillard reaches the end of the "6 days-6 weeks-6 months" cycle he explored around "The First 100 Days of the New CISO", and looks at what happens next, and how CISOs can continue to drive change
JC Gaillard reaches the "6 months" part of his journey throughout the "First 100 Days of the New CISO"; in this episode, how to build an execution framework to support the strategic vision defined earlier, and why governance is key at this stage to support lasting change
JC Gaillard continues developing his "6 days - 6 weeks - 6 months" model, framing the first 100 days of the new CISO; in this episode, the six weeks horizon, and how to continue building a strategic framework addressing the key challenges of the new CISO role
JC Gaillard continues to look back at his 2017-2018 series of articles about "The First 100 Days of the New CISO"; in this episode, he looks into the challenges of the first week, and why it is key to understand the firm, its people and its culture from the start
We enter the second part of our third series and JC Gaillard starts exploring and revisiting his 2017-2018 series of articles entitled "The First 100 Days of the New CISO"; in this episode, why context is key and how to assess it, looking in turn at the profile of the person, the nature of the role and the maturity of the firm
JC Gaillard reaches the final part in the re-examination of his 2015 series titled "The CIO Guide to a Successful Cyber Security Practice"; in this episode, why it is key to think in terms of process first when architecting a cyber security practice, and not in terms of technical tools
JC Gaillard reaches the 7th key management pitfall to avoid in his re-assessment of his 2015 series of articles entitled "The CIO Guide to a Successful Cyber Security Practice"; in this episode, why it is key to look at cyber security as a structured practice, and not just a collection of tactical activities and technical projects
JC Gaillard reaches a key point in his journey through the 8 key management pitfalls for CIOs and CTOs to avoid when building or rebuilding cyber security practices; in this episode, why it is key to see cyber security not just as a technology discipline, and to build it as a cross-silo practice from the start
JC Gaillard moves onto his 5th key management pitfall to avoid when building or rebuilding effective and efficient cyber security practices; in this episode, why it is key to think in terms of operating model and work with all stakeholders including HR, in the definition and distribution of cyber security accountabilities and responsibilities
JC Gaillard continues his re-examination of his 2015 series of articles titled "The CIO Guide to a Successful Cyber Security Practice"; in this episode, why it is key to look beyond the short term and think in terms of process to drive effective and lasting change
JC Gaillard continues exploring and updating his 2015 series on the "CIO Guide to a Successful Cyber Security Practice"; in this episode, why throwing money at the problem is rarely the solution to maturity development around cyber security and why trust is paramount in the relation between the CISO and senior execs
JC Gaillard continues to look back at his 2015 articles series "The CIO Giude to a Successful Cyber Security Practice" and highlights why risk management alone can no longer be the beating heart of cyber security practices
JC Gaillard looks back at his 2015 series of articles published on the Corix Partners blog under the title of "The CIO Guide to a Successful Cyber Security Practice"; in this episode, he re-examines the first pitfall to avoid for CIOs and why cyber security cannot just be seen as an "enabler"
JC Gaillard is joined by Chris Burtenshaw from Strata Security to discuss how the log4j incident unfolded and was handled, and the lessons that can be learnt from the pas few months
JC Gaillard is joined by Cristina Contero from Aphaia to follow up on earlier podcasts episodes on GDPR and review what has changed over the past 6 to 8 months since our last podcast on the theme with Bostjan Makarovic
JC Gaillard is joined again by guest Steve Lamb, who animated the launch of the first series of the podcast last year; together they look back at the drivers that have shaped cyber security throughout 2021, and more generally throughout the COVID pandemic
JC Gaillard is joined by Richard Preece, Founder & Director, DA Resilience to discuss how the pandemic has affected cybersecurity governance, controls appetite and risk management from the Board down, and how exponential changes over the next decade are going to impact those trends
JC Gaillard is joined by Natasha McCabe to discuss the leadership lessons which can be learned from having held both CISO and CIO roles, and having seen cyber security from the two sides of the fence
JC Gaillard is joined by Oscar O'Connor to discuss "Playing the Triangles", his latest piece on the Corix Partners blog: A reflection on business and security transformation dynamics in the post-covid era
JC Gaillard is joined by Rayna Stamboliyska to look back at the cyber security skills back, its implications and how to address it through better talent management, clearer career paths and a greater emphasis on diversity
JC Gaillard is joined with Hani Banayoti from CyberSolace to explore the impact the COVID-19 pandemic has had on the cyber insurance sector and what can be expected going forward in terms of new dynamics
JC Gaillard is joined by Alexa Glynn, from Rabobank Australia & New Zealand, to discuss how you transition from security roles into IT management roles and why security professionals don't have to feel condemned to hopping between security jobs
JC Gaillard is joined again by guest Bostjan Makarovic from Aphaia to discuss the impact of the Schrems II ruling on GDPR compliance and data transfers between the EU and the US
JC Gaillard is joined by cyber security expert Steven O'Sullivan to explore the issues surrounding IT and OT convergence and their implications for cyber security at large across industry sectors
JC Gaillard is joined by Chris Burtenshaw from Strata Security; together they explore the meaning of observability in the cyber security space: Is it just hype over substance? or is there more to it than meet the eye?
JC Gaillard is joined by Bostjan Makarovic from Aphaia for a great discussion on GDPR, the size of fine and role of regulators, the risk of irrelevance they may face if they keep things imbalanced, and the impact of the Schrems II ruling
JC Gaillard is joined by experienced operational resilience consultant Nick Simms to explore what resilience really means in business terms and where cyber resilience needs to fit within a broader business resilience framework
JC Gaillard is joined by Richard Preece, director of DA Resilience, to explore how best to frame the conversation at Board level around cyber security in order to engineer effective and efficient engagement and top-down dynamics
.By any account the last year has been crazy. So much had to change so quickly and that included cyber security. In this episode we discuss the key lessons learned about security and privacy.
COVID has led many organizations to rush their provision or remote access to their employees and many have accelerated their digital transformation programmed. We discuss the role of the CISO in this context.
We discuss a recent survey that reveals the continued prevalence of ransomware and the shocking amount that organizations typically pay. We talk about how to protect organizations from becoming victims
In this episode we discuss the need for top down engagement by the board to bring life into the to security and privacy strategy of their organisation. We look at the importance of embedding these important considerations into the Environmental, Social and Governance (ESG).
Following the recent announcement from the ICO of significantly reduced fines for BA and Marriott the question has to be asked "Where are the landmark cases of fines in the order of 4% of revenue for huge scale breaches?". Clearly during the pandemic the travel and hospitality industries are under great financial strain but since GDPR came in over two years ago there haven't been any fines that have been anywhere near the expected magnitude.
.We’re joined by Zsuzsanna Berenyi from the London Stock Exchange Group who shares her experience on how to drive cultural change to embed security awareness into organizations.
In this episode we are joined by Hani Banayoti (hani.banayoti@cybersolace.co.uk) from Cyber Solace to discuss the ways in which the cyber insurance market has changed over the last ten years. We look at the drivers towards organisations choosing to pay for cyber insurance, it's role in helping them keep the lights on if they are breached and the trends with regard to ransomware and GDPR.
Incoming CISOs clearly have to identify and put out fires. In this episode we discuss why many CISOs get stuck in this phase. We look at ways to enable transformative change.
We discuss why it’s important to think carefully about how to ensure the Minimum Viable Product (MVP) software written by startups pays attention to the requirements of privacy and security
Chris Burtenshaw, CEO of Strata Security joins us to discuss how many organizations have far too many security products and how to address the complexity and management overhead they often bring.
We discuss the extent to which there are opportunities in the cyber industry and how to encourage people to join
Given the financial strain caused by COVID-19 which has been especially severe on the hospitality and airline sectors the likelihood of large fines being imposed on Marriot and BA looks low - what does this mean for compliance?
Zero Trust Networking promises much and is being touted extensively... how much sense does it make at the moment?
The threat to business continuity posed by malicious actors using ransomware isn’t new but it’s causing pain to many. The most recent high profile attack was on Garmin - a company Steve relies upon to help with his marathon training
I’m this episode we discuss the need for privacy to be carefully considered and for appropriate controls to be applied together with the challenges for GDPR regulators in light of the COVID pandemic.
Faced by constant reports of cyber-attacks in the media, most small and medium-size organisations have woken up to the reality of cyber threats over the past few years. Many still don’t really know what to do to protect themselves and turn to “virtual CISO” services for assistance. While this is better than doing nothing or relying blindly on the security of cloud providers, those externalised, part-time services – often delivered remotely – are rarely the magic bullet they pretend to be…
In this episode we discuss how to bring constructive change by culture and top down leadership
We discuss the challenges of ensuring that code that’s written either in-house or commissioned from a third party follows the Security Development Life Cycle
This is the first in a series of Cyber Security Transformation Podcasts. Each week JC and Steve will discuss the interesting cyber next stories and our own experiences with clients.
Jean Christophe Gaillard
M: +44 (0)7733 001 530
E: jcgaillard@corixpartners.com
https://twitter.com/@Corix_JC
Steve Lamb
M: +44 (0)75 0800 8864
E: steve.lamb@corixpartners.com
https://twitter.com/actionlamb