CISO Series Podcast

CISO Series Podcast

By David Spark, Mike Johnson, and Andy EllisNewsTechnologyTech News
Download on the App Store

CISO Series Podcast episodes

  • You Can't Leak What You Don't Collect

    All links and images for this episode can be found on CISO Series.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining us is our sponsored guest, Jeremiah Roe, advisory CISO, OffSec.

    In this episode:

    • What happens as data minimization in the US changes from a potential policy goal to a regulatory imperative?

    • How does this impact the rest of the industry?

    • How do CISOs start getting ready for compliance?

    • How to improve cybersecurity training and development?

    Thanks to our podcast sponsor, OffSec

    OffSec helps companies like Cisco, Google, and Salesforce upskill cybersecurity talent through comprehensive training and resources. With programs ranging from red team and blue team training and more, your team will be ready to face real-world threats. Request a free trial for your team to explore OffSec's learning library and cyber range.

    35 min
  • Our Help Desk Plaque Reads "Over 100,000 Threat Actors Served"

    All links and images for this episode can be found on CISO Series.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining us is our guest, Martin Mazor, vp and CISO, onsemi.

    In this episode:

    • Has the shine worn off the cybersecurity promise of MFA?

    • Why are threat actors increasingly finding ways to get around it?

    • Given the high profile attacks we've seen getting around MFA, how much security stock should we put into it going forward?

    Thanks to our podcast sponsor, Material Security

    Material Security is a multi-layered email threat detection & response toolkit designed to stop attacks and reduce the threat surface across all of Microsoft 365 and Google Workspace. Learn more at material.security.

    36 min
  • Can't Talk, I'm Onboarding My Kids To Their First Soccer Practice (Live in Mountain View, CA)

    All links and images for this episode can be found on CISO Series.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is our guest, TC Niedzialkowski, CISO, Nextdoor.

    In this episode:

    • Has the line between work and personal devices blurred?

    • Why are we seeing signs that that line no longer exists for employees?

    • What is the path of cybersecurity to keep company data secured when its continually commingling with personal devices?

    Thanks to our podcast sponsors, Eclypsium and Normalyze

    Eclypsium is helping enterprises and government agencies mitigate risks to their infrastructure from complex technology supply chains. Our cloud-based and on-premises platform provides digital supply chain security for software, firmware and hardware in enterprise infrastructure. Get started today at eclypsium.com/spark

    Where is my data? Is it sensitive? Who has access to the data? What are the risks? What is the cost of exposure? Am I compliant now? Enter Normalyze. Normalyze's agentless, machine-learning scanning platform continuously discovers sensitive data, resources, and access paths in all cloud environments. Learn more.

    45 min
  • I Really Shouldn't Have Agreed to Variable Rate Technical Debt

    All links and images for this episode can be found on CISO Series.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining me is our sponsored guest, Aaron Shaha, CISO, CyberMaxx.

    In this episode:

    • Is technical debt an inevitability in any organization?

    • How do you go about "paying it down?"

    • How do you decide when you need a systematic refresh and when can you kick the can down the road a little longer?

    Thanks to our podcast sponsor, CyberMaxx

    CyberMaxx offers MaxxMDR, our next-generation managed detection and response (MDR) solution that helps customers assess, monitor, and manage their cyber risks. MaxxMDR fuels defensive capabilities with insights from offensive security, DFIR, and threat hunting, on top of a technology-agnostic deployment model. We think like an adversary but defend like a guardian.

    36 min
  • We'll Invest in Resilience as Soon as the Ransom Payment Clears

    All links and images for this episode can be found on CISO Series.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining us is my guest, Thom Langford, CISO, Velonetic.

    In this episode:

    • Why do lots of businesses pledge to never pay ransomware demands?

    • And why do their priorities quickly change when they need to get the business back to normal after an attack occurs?

    • What good is a pledge like that without the infrastructure and organizational commitment to make it possible?

    Thanks to our podcast sponsor, CyberMaxx

    CyberMaxx offers MaxxMDR, our next-generation managed detection and response (MDR) solution that helps customers assess, monitor, and manage their cyber risks. MaxxMDR fuels defensive capabilities with insights from offensive security, DFIR, and threat hunting, on top of a technology-agnostic deployment model. We think like an adversary but defend like a guardian.

    36 min
  • We Could Lower Risk If We Shrunk Our Business

    All links and images for this episode can be found on CISO Series.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining me is our sponsored guest, Matt Radolec, vp, incident response and cloud operations, Varonis.

    In this episode:

    • Why is retaining cyber talent so hard?

    • How can organizations keep an employee from going elsewhere?

    • Why do organizations often not prioritize the factors to keep key employees?

    Thanks to our podcast sponsor, Varonis

    Ready to reduce your risk without taking any? Try Varonis' free data risk assessment. It takes minutes to set up and in 24 hours you'll have a clear, risk-based view of the data that matters most and a clear path to automated remediation. Get started for free today.

    39 min
  • Our Benefits Include Medical, Dental, and Burnout

    All links and images for this episode can be found on CISO Series.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining us is our guest, Joshua Brown, vp and global CISO, H&R Block.

    In this episode:

    • Why is retaining cyber talent so hard?

    • How can organizations keep an employee from going elsewhere?

    • Why do organizations often not prioritize the factors to keep key employees?

    Thanks to our podcast sponsor, CyberMaxx

    CyberMaxx offers MaxxMDR, our next-generation managed detection and response (MDR) solution that helps customers assess, monitor, and manage their cyber risks. MaxxMDR fuels defensive capabilities with insights from offensive security, DFIR, and threat hunting, on top of a technology-agnostic deployment model. We think like an adversary but defend like a guardian.

    44 min
  • Your Biggest Threats Don't Get a Ransom Payment, They Get a Paycheck

    All links and images for this episode can be found on CISO Series.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining me is our guest, Alex Green, CISO, Delta Dental.

    In this episode:

    • Is it true that employees cause as many significant cybersecurity incidents as outside threat actors?

    • Does this come down to a lack of awareness or poorly designed security implementation?

    • And what can we do to improve this situation?

    Thanks to our podcast sponsor, Silk Security

    Silk makes it easy for security teams to resolve more critical cyber risks in a fraction of the time. Instead of toiling over spreadsheets, and watching alert backlog graphs go up, Silk helps security teams contextualize, prioritize and collaborate with stakeholders in IT to regain control over their risk posture.

    37 min
  • A Stressed CISO Is a Happy CISO

    All links and images for this episode can be found on CISO Series.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining us is our guest, Shawn Bowen, svp and CISO, World Kinect Corporation.

    In this episode:

    • Is it true that CISOs feel their jobs are harder than ever with higher levels of stress?

    • Yet why does research also show that CISO job satisfaction increasing?

    • How do we make sense of this contradiction?

    Thanks to our podcast sponsor, Silk Security

    Silk makes it easy for security teams to resolve more critical cyber risks in a fraction of the time. Instead of toiling over spreadsheets, and watching alert backlog graphs go up, Silk helps security teams contextualize, prioritize and collaborate with stakeholders in IT to regain control over their risk posture.

    39 min
  • BREAKING: "Department of No" Upgraded to "Department of Slow"

    All links and images for this episode can be found on CISO Series.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining me is our sponsored guest, Nadav Lotan, product management team leader, Cisco.

    In this episode:

    • How can security teams do their jobs without seeming like an impediment to developers?

    • Why can this relationship seem oppositional?

    • How can both sides work together to better secure software without seeming like a road block?

    Thanks to our podcast sponsor, Panoptica, Cisco's Cloud Application Security Platform

    Panoptica, Cisco's Cloud Application Security solution, provides end-to-end lifecycle protection for cloud native application environments. It empowers organizations to safeguard their APIs, serverless functions, containers, and Kubernetes environments. Panoptica ensures comprehensive cloud security, compliance, and monitoring at scale, offering deep visibility, contextual risk assessments, and actionable remediation insights for all your cloud assets.

    37 min

About CISO Series Podcast

From the publisher's feed

Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.

More shows like CISO Series Podcast

Hacked by Hacked

Hacked

192 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

374 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

652 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Click Here by Recorded Future News

Click Here

423 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,068 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

180 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners

CISO Tradecraftยฎ by G Mark Hardy & Ross Young

CISO Tradecraftยฎ

48 Listeners

Security You Should Know by CISO Series

Security You Should Know

9 Listeners