CISO Series Podcast

CISO Series Podcast

By David Spark, Mike Johnson, and Andy EllisNewsTechnologyTech News
Download on the App Store

CISO Series Podcast episodes

  • This Security Crisis Is the Perfect Time to Tell You I Was Right

    All links and images for this episode can be found on CISO Series.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining me is our guest this week, Mike Kelley, CISO, EW Scrips.

    In this episode:

    • Why do a lot of security professionals feel unheard?
    • Does this frustration lead to some turning into scolds during a security incident, quick to say "I told you so"?
    • How do you manage these security pros when they don't feel heard, both before and during a crisis?

    Thanks to our podcast sponsors, Praetorian

    Praetorian helps companies adopt a prevention-first cybersecurity strategy by actively uncovering vulnerabilities and minimizing potential weaknesses before attackers can exploit them.

    43 min
  • You're Not Leaving This House Until You Cover Up That LLM

    All links and images for this episode can be found on CISO Series.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining me is our guest, Richard Ford, CTO, Praetorian.

    In this episode:

    • Why do many CISOs think adopting new LLM-based tools will make breaches more likely?
    • Why the rush to throw money at them?
    • How do you go about building a security program that doesn't depend on individuals?

    Thanks to our podcast sponsors, Praetorian

    Praetorian helps companies adopt a prevention-first cybersecurity strategy by actively uncovering vulnerabilities and minimizing potential weaknesses before attackers can exploit them.

    41 min
  • We Got This Far Without Hiring a Prompt Engineer

    All links and images for this episode can be found on CISO Series.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining me is our guest, Suresh Vasudevan, CEO, Sysdig.

    In this episode:

    • What will the employment landscape look like with Generative AI becoming the next big thing?
    • Will we be hiring prompt engineers in a few years?
    • Or will it become like putting "search engine proficiency" on your resume?

    Thanks to our podcast sponsors, Sysdig

    For businesses innovating in the cloud, every second counts. Sysdig strengthens cyber resilience by reducing the attack surface, detecting threats in real time, and accelerating incident response. Our platform correlates signals across cloud workloads, identities, and services to enable businesses to prioritize risks and act decisively. Sysdig. Secure every second.

    46 min
  • Ugh, Lawyers Take All the Fun Out of Surviving a Cyberattack (LIVE in Las Vegas)

    All links and images for this episode can be found on CISO Series.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and sponsored co-host Jason Sabin, CTO, DigiCert. Joining us is our guest, Alexandra Landegger, executive director of security, Collins Aerospace.

    In this episode:

    • Are CISOs prepared for the legal surprises that can come in the aftermath of a cyberattack?
    • What about the legal fallout that can occur afterward?
    • How does a security team work with legal beforehand to address these issues when drawing up incident response?

    Thanks to our podcast sponsors, DigiCert

    DigiCert is a leading global provider of digital trust, the infrastructure that enables individuals and businesses to have confidence that their digital interactions are secure. DigiCert's award-winning solutions enable organizations to establish, manage, and extend public and private trust across their digital footprint, securing users, servers, devices, software and content.

    45 min
  • Dear Abby: Should I Sell to a CISO During a Cyberattack? (LIVE in Mountain View)

    All links and images for this episode can be found on CISO Series.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining me is our guest, Kurt Sauer, CISO, Docusign.

    We recorded in front of a live audience at Microsoft's offices in Mountain View, CA as part of the ISSA-Silicon Valley chapter meeting. Check out all the photos from the event.

    In this episode:

    • Is a high profile cyberattack the best time for salespeople to come out of the woodwork asking if the affected CISO would like to see their product, which would have helped prevent the attack?
    • Is there any way for a vendor to positively reach out to victims after a cyberattack?
    • Also, what could be some effective ways to invest IP with generative AI to create value for the organization?

    Thanks to our podcast sponsors, Veza, Sysdig, and SlashNext

    75% of breaches happen because of bad permissions. The problem is that you don't know exactly WHO has access to WHAT data in your environment. For example, roles labeled as "read-only" can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every app—across your environment.

    For businesses innovating in the cloud, every second counts. Sysdig strengthens cyber resilience by reducing the attack surface, detecting threats in real time, and accelerating incident response. Our platform correlates signals across cloud workloads, identities, and services to enable businesses to prioritize risks and act decisively. Sysdig. Secure every second.

    SlashNext Complete delivers zero-hour protection for how people work today across email, mobile, and browser apps. With SlashNext's generative AI to defend against advanced business email compromise, smishing, spear phishing, executive impersonation, and financial fraud, your people are always protected anywhere they work. Request a demo today.

    45 min
  • We're Not Home. Please Leave Your Company's Data After the Beep

    All links and images for this episode can be found on CISO Series.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining me is our guest, Arvin Bansal, former CISO for Nissan Americas.

    In this episode:

    • Why are so many companies unprepared for phone-based social engineering?
    • Why do many orgs not give this attack surface the attention it deserves?
    • Are we doing enough to support whistleblowers in cybersecurity?

    Thanks to our podcast sponsor, Palo Alto Networks

    As cloud attacks increase, how should AppSec respond? Hear from Daniel Krivelevich, CTO of AppSec at Palo Alto Networks, as he dives into modern application security strategies that can help teams defend their engineering ecosystems from modern attacks. Watch now to level up your AppSec program.

    44 min
  • Hey, Let's Merge Our Technical Debt With Your Understaffed Security Team! (LIVE in Miami)

    All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Adam Zoller, svp, CISO at Providence. Joining me is our guest Sam Jacques, vp of clinical engineering, McLaren Health Care.

    In this episode:

    • When should cybersecurity be brought into the discussion when a merger is underway?
    • Why is security always going to be an issue in a merger or acquisition?
    • If we know it's so important, why does it always feel like we're reinventing the wheel each time?

    Thanks to our podcast sponsor, Claroty

    Claroty enables varied sectors to protect their cyber-physical systems, known as the Extended IoT. The platform integrates seamlessly, offering comprehensive controls for visibility, risk management, network protection, and more. Trusted by global leaders, Claroty operates in hundreds of organizations worldwide. Headquartered in NYC, it spans Europe, Asia-Pacific, and Latin America.

    45 min
  • I Taught DeNiro Security Theater, I Can Teach You.

    All links and images for this episode can be found on CISO Series.

    In principle, we can generally all agree that security theater is a waste of time for security teams. But the reality is that these are things that look good, so it can be hard to justify to non-technical leadership why you're eliminating something they see as secure. So how can we positively identify actual security theater practices and how do we communicate that to the rest of the organization?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining me is our guest, Davi Ottenheimer, vp of trust and digital ethics, Inrupt.

    Thanks to our podcast sponsor, Sysdig

    For businesses innovating in the cloud, every second counts. Sysdig strengthens cyber resilience by reducing the attack surface, detecting threats in real time, and accelerating incident response. Our platform correlates signals across cloud workloads, identities, and services to enable businesses to prioritize risks and act decisively. Sysdig. Secure every second.

    In this episode:

    • Is security theater a waste of time for security teams?
    • Why can it be hard to justify to non-technical leadership why you're eliminating something they see as secure?
    • How can we positively identify actual security theater practices and how do we communicate that to the rest of the organization?
    40 min
  • A CEO's Guide To Ignoring Your Security Program (LIVE in Santa Monica)

    All links and images for this episode can be found on CISO Series.

    Usually the buck stops with the CEO. But for a CISO, what do you do when a CEO wants to exempt themselves from your security program? Whether it's granting privileged network access or just ignoring protocols, it can put a CISO in a tough spot. So how do you deal with a leader that thinks they're above the controls you have in place? Is it enough to document your disagreement or is there anything else you can do in that position?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and John C. Underwood, VP, information security, Big 5 Sporting Goods. Joining me is our guest, Joshua Scott, Head of Security and IT, Postman.

    Thanks to our podcast sponsor, Veza

    75% of breaches happen because of bad permissions. The problem is that you don't know exactly WHO has access to WHAT data in your environment. For example, roles labeled as "read-only" can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every app—across your environment.

    In this episode:

    • For a CISO, what do you do when a CEO wants to exempt themselves from your security program?
    • How do you deal with a leader that thinks they're above the controls you have in place?
    • Is it enough to document your disagreement or is there anything else you can do in that position?
    45 min
  • Security Awareness Lifecycle: Turn On, Tune In, Drop Out

    All links and images for this episode can be found on CISO Series.

    When it comes to security awareness, the advice generally doesn't change. There are a set of best practices that have proven to be effective. So we know what we want to tell people. Communicate it consistently. So how do we relay that information without sounding like a broken record?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Steve Zalewski. Joining us is our sponsored guest, Daniel Krivelevich, CTO for Appsec, Palo Alto Networks.

    Thanks to our podcast sponsor, Palo Alto Networks

    As cloud attacks increase, how should AppSec respond? Hear from Daniel Krivelevich, CTO of AppSec at Palo Alto Networks, as he dives into modern application security strategies that can help teams defend their engineering ecosystems from modern attacks. Watch now to level up your AppSec program.

    In this episode:

    • What security measures have been the most successful in preventing cyberattacks?
    • What do we need to better understand about misconfigurations to better secure the cloud?
    • How do we relay this information without sounding like a broken record?
    39 min

About CISO Series Podcast

From the publisher's feed

Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.

More shows like CISO Series Podcast

Hacked by Hacked

Hacked

192 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

374 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

652 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Click Here by Recorded Future News

Click Here

423 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,068 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

180 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners

CISO Tradecraft® by G Mark Hardy & Ross Young

CISO Tradecraft®

48 Listeners

Security You Should Know by CISO Series

Security You Should Know

9 Listeners