
Sign up to save your podcasts
Or


Send us fan mail via text by clicking here!
Welcome to this action packed episode of the CISO MindMap Podcast. The lads are biting off a big chunk of the 2025 recommendations by handling numbers 4, 5 and 6.
Recommendation number 4 is Cyber Resilience and Ransomware. The gents discuss industry impacts and the role of AI when it comes to how attackers come at their targets. It’s notable to focus on an organization's ability to respond to an event because minimizing impacts to business operations is critical. Also discussed is the importance of planning, particularly the Business Impact Analysis and the importance of testing.
Recommendation number 5 is about metrics. The recent trend towards more business focused metrics continues and ensuring your metrics are showing improvements over time. In addition to trends, comparing your metrics to industry standards or benchmarks is also a good strategy.
Recommendation number 6 is a more general recommendation to improve your cyber hygiene. Cyber professionals can’t simply jump to new priorities and take on new initiatives without losing site of the basics. Whether it is basic visibility or management of company assets, focusing on cyber hygiene will also be critical.
https://rafeeqrehman.com/
https://www.linkedin.com/in/scott-a-hawk/
https://www.linkedin.com/in/rafeeq/
Send us fan mail via text by clicking here!
Back from a few weeks off, the lads come together to discuss recommendation number 3 from Rafeeq’s 2025 CISO MindMap, Identify and Manage Security Debt. This is a practical discussion that hopefully offers some ideas to improve the overall operations of your security program.
After a quick recap of the first 2 recommendations from the 2025 CISO MindMap, your hosts begin defining security debt in the context of software, hardware and systems. The concept of risk management is quickly brought into scope as a key component to understanding and managing this debt. To help pull in as many potential targets as possible, they discuss the nature of the growth of security debt.
Of course, this podcast is not only about admiring the problem, but providing some helpful methodologies to begin addressing your security debt. Important concepts here include 1) creating a central place to quantify and manage the debt, maye a risk register. 2) be sure to assign some dollar value to the effort and 3) make this effort part of a program. Of course the goal is to flatten the curve of growth of the debt and hopefully begin a downward trend.
For folks just starting their careers, we hope this topic gives you some insight into what the senior people in the organization are concerned with. As you go about your daily routine, you can help the organization by identifying aspects of your function that can impact growth of security debt.
https://rafeeqrehman.com/
https://www.linkedin.com/in/scott-a-hawk/
https://www.linkedin.com/in/rafeeq/
Send us fan mail via text by clicking here!
In this episode of the CISO MindMap Podcast, hosts Scott Hawk and Rafeeq Rehman dive into Recommendation #2 from the 2025 CISO Mind Map: Consolidate and Rationalize Security Tools.The discussion centers around the challenges organizations face with tool overload, the diminishing returns of excessive tools, and strategies to optimize cybersecurity operations.
Key Takeaways:
Thank you for listening! Don’t forget to subscribe, rate, and review the podcast wherever you listen!
https://rafeeqrehman.com/
https://www.linkedin.com/in/scott-a-hawk/
https://www.linkedin.com/in/rafeeq/
Send us fan mail via text by clicking here!
Is it too soon for another podcast on AI? The gents think not. The first recommendation of the 2025 CISO MindMap is about securing AI and this week’s podcast attempts to go fairly deep into real-world experiences and recommendations. Your hosts try not to assume everyone is tuned in to all the different types, modes and capabilities of AI, so hopefully you’ll find this episode to be basic enough for newcomers and detailed enough to take action.
In Rafeeq’s blog, he makes several recommendations which are discussed in this episode.
References mentioned in this episode.
https://rafeeqrehman.com/2025/01/11/how-to-use-genai-in-cybersecurity-operations/
https://rafeeqrehman.com/2024/06/30/run-llm-models-on-a-macbook/
https://rafeeqrehman.com/
https://www.linkedin.com/in/scott-a-hawk/
https://www.linkedin.com/in/rafeeq/
Send us fan mail via text by clicking here!
The lads are excited to be back with a new CISO MindMap Podcast and this episode is extra special. They’re introducing the 2025 Edition of the CISO MindMap, available immediately at Rafeeq’s website. The latest edition makes six recommendations that will be introduced in this episode. Expect to go deeper into each recommendation in the coming weeks.
This year's recommendations are:
#1 - it is time for securing genai
#2 - consolidate and rationalize security tools
#3 - identify and manage security debt
#4 - ransomware and cyber resilience
#5 - create meaningful metrics
#6 - improve cyber hygiene
Be sure to subscribe to catch the ongoing discussion and visit Rafeeq’s website for the full CISO MindMap blog and download.
From Rafeeq’s website:
The job of a Chief Information Security Officer (CISO) is complex. Many individuals outside the realm of cybersecurity often underestimate the intricacies involved in a security professional’s role. Since its inception in 2012, the CISO MindMap has served as a valuable educational resource, offering insights into CISO responsibilities and aiding security professionals in crafting and enhancing their security programs. Continuously adapting to reflect the evolving landscape of cybersecurity, the CISO MindMap has been updated to accommodate the latest developments in the field. Here is the most recent iteration of the CISO MindMap for 2025, featuring numerous enhancements and fresh recommendations for the next 12-18 months covering the year 2025-26.
https://rafeeqrehman.com/
https://www.linkedin.com/in/scott-a-hawk/
https://www.linkedin.com/in/rafeeq/
Send us fan mail via text by clicking here!
In this episode, Rafeeq and Scott discuss the many considerations involved with building your own Security Operations Center SOC. While in no way a comprehensive analysis, the discussion attempts to make the concepts manageable. If you're a small company growing past a few IT headcount, the topic should help you create a vision for your situation. If you’re a larger company and looking to expand, these pointers may be of help
This conversation focused on budgeting, structure, and decision-making processes, including the choice between building in-house or outsourcing. The discussion covered various aspects of SOC operations, such as staffing requirements, skill development, and the importance of continuous learning in the face of evolving threats. Also emphasized is the need for proper shift management, stress tolerance, and the value of tabletop exercises and purple teaming in assessing SOC effectiveness.
Rafeeq wrote a great book on this topic. Have a look on Amazon here.
Check out the calculator Rafeeq mentions in the podcast here.
https://rafeeqrehman.com/
https://www.linkedin.com/in/scott-a-hawk/
https://www.linkedin.com/in/rafeeq/
Send us fan mail via text by clicking here!
Welcome to Episode 7 of the CISO MindMap Podcast. This week, Rafeeq and Scott discuss a range of topics related to business acumen. Tucked away in this topic are references to some common themes of this podcast. Themes such as brand-building, business performance, and business alignment are spread throughout the conversation.
This episode breaks down the business acumen topic into five areas:
https://rafeeqrehman.com/
https://www.linkedin.com/in/scott-a-hawk/
https://www.linkedin.com/in/rafeeq/
Send us fan mail via text by clicking here!
This week, Scott and Rafeeq go wide across the CISO MindMap discussing six key concepts for every Security Operations Center. As the conversation kicks off, Rafreeq takes a few minutes to discuss a recent FBI warning related to texting.
The six elements discussed are People/Staffing, Processes, Technology Stack, Governance, Data Sources, and Threat Intelligence. Check out Rafeeq’s blog for written commentary on these topics.
During the conversation, Scott mentions a security incident from Christmas Eve 2024. He laments not recalling the specifics but as predicted, it is well documented. That incident was a hack of a Chrome extension.
Breach Stats: Scott mentioned that certain statistics are widely available to search engines. Here are the results from a ChatGPT request from February 2025.
1. Time to Detect and Contain a Breach:
2. Attacker Dwell Time:
3. Average Cost of a Data Breach:
4. Impact of Detection Time on Breach Cost:
https://rafeeqrehman.com/
https://www.linkedin.com/in/scott-a-hawk/
https://www.linkedin.com/in/rafeeq/
Send us fan mail via text by clicking here!
It’s January 2025 and this podcast is the first of the year. Our first topic is Artificial Intelligence (AI). Or said more specifically, Generative AI. GenAI represents a potential for massive change in modern society. Although various forms of AI have been working their way into security tools and workflows for years, Generative AI has burst on the scene and leveraging it should be a top priority of security professionals.
In this episode, your hosts are covering content from both Rafeeq’s CISO MindMap and Cybersecurity Learning Saturday. The first topic is GenAI risk, assigned to 3 buckets.
The second topic is a review of emerging GenAI use cases in security. Rafeeq documents at least 6 but there will be many more.
Resources mentioned in this episode:
https://rafeeqrehman.com/
https://www.linkedin.com/in/scott-a-hawk/
https://www.linkedin.com/in/rafeeq/
Send us fan mail via text by clicking here!
Numerous factors determine how long a CISO remains in their position and some can be controlled by the individual. In this episode of the CISO MindMap Podcast, Rafeeq and Scott discuss both the pitfalls and success criteria pertinent to the CISO role. From budgets to culture, they tackle some of the key elements driving the success or failure of the cybersecurity organization.
https://rafeeqrehman.com/
https://www.linkedin.com/in/scott-a-hawk/
https://www.linkedin.com/in/rafeeq/
From the publisher's feed
Featuring Rafeeq Rehman, the creator of the CISO MindMap, each week we discuss topics related to the functions of the Chief Information Security Officer. Topics range from the technology…