CISO Series Podcast

CISO Series Podcast

By David Spark, Mike Johnson, and Andy EllisNewsTechnologyTech News
Download on the App Store

CISO Series Podcast episodes

  • Cyber Advice So Generic, You'll Assume It Came from ChatGPT

    All links and images for this episode can be found on CISO Series.

    Shifting Left is so five years ago. Advice and best practices are great, but context is king. Is there a mixture of best practices AND doing what's right for your business that's actually practical?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Steve Zalewski. Joining us for the episode is our sponsored guest Gaurav Banga, CEO, Balbix.

    Thanks to our podcast sponsor, Balbix

    Balbix is a cyber risk quantification platform that discovers and manages all your cyber assets, identifies and prioritizes vulnerabilities, and delivers a monetary assessment of cyber risk. This enables CISOs to articulate the value of risk to the board and obtain support and budgets for security programs.

    In this episode:

    • What are your most successful tactics when talking to the boardroom?
    • Is there a mixture of best practices AND doing what's right for your business that's actually practical?
    • What have you heard enough with automation and what would you like to hear a lot more?
    37 min
  • Vendors Are From Mars. Their Security Is From Venus.

    All links and images for this episode can be found on CISO Series.

    There are so many third party vendors we want to work with, but uggh, their security and privacy is so troublesome. Is it only the security department's job to vet these partners or should everyone have a responsibility of keeping tabs on third party security?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Our guest is Phil Beyer, former head of security, Etsy.

    Thanks to our podcast sponsor, Balbix

    Balbix is a cyber risk quantification platform that discovers and manages all your cyber assets, identifies and prioritizes vulnerabilities, and delivers a monetary assessment of cyber risk. This enables CISOs to articulate the value of risk to the board and obtain support and budgets for security programs.

    In this episode:

    • There are many third party vendors that CISOs & practitioners want to work with, but why is their security and privacy so troublesome?
    • Is it only the security department's job to vet these partners or should everyone have a responsibility of keeping tabs on third party security?
    • What can frontline employees do to manage third-party risk?
    40 min
  • We're So Special Gartner Hasn't Even Thought Of Our Category Yet

    All links and images for this episode can be found on CISO Series.

    Do you know what security categories were created this year? I have no idea. Do you know which ones were deleted? I don't think any. Is category growth designed to make more money for the industry? Does it help customers build a better security strategy? It seems like a necessary evil that just confuses customers. The number of categories never decreases or replaces old categories.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Our sponsored guest is Maxime Lamothe-Brassard (@_maximelb), CEO and co-founder at LimaCharlie.

    Thanks to our podcast sponsor, LimaCharlie

    LimaCharlie is inviting you for the unveiling of the SecOps Cloud Platform during a two-hour LinkedIn Live event on Wednesday, July 19th, starting at 10:00am PST. For every registrant, LimaCharlie will be donating $5 to the Internet Archive. Register for the event at limacharlie.io or on the LimaCharlie LinkedIn page.

    In this episode:

    • Do you know what security categories were created this year? Do you know which ones were deleted?
    • Is category growth designed to make more money for the industry?
    • Does it help customers build a better security strategy?
    42 min
  • Who's in Charge of Stopping Stupid Ideas? (LIVE in Tel Aviv)

    All links and images for this episode can be found on CISO Series.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and guest co-host Jesse Whaley, CISO, Amtrak. Our guest was Paul Branley, CISO, TSB Bank.

    We recorded this episode in front of a live audience in Tel Aviv as part of Team8's CISO Summit 2023. CISO Series is honored to have been invited to record our show at the event.

    Thanks to our podcast sponsor, Team8

    Team8 is a global venture group that builds and invests in early stage companies focused on digital transformation: cybersecurity, data, fintech and digital health. Its strong expertise in cyber is the backbone of Team8's CISO Village - a community of hundreds of CISOs who enjoy access to thought leadership, networking events, and partner with Team8 to support its company building process.

    In this episode:

    • Why should you NEVER boast about how good your security is?
    • When upskilling your staff, how do you identify the knowledge that must be learned? Who will learn it? Who will provide it?
    • What does this do to your current security if people are spending time teaching and learning?
    42 min
  • Password Rules Make Us Feel More Secure

    All links and images for this episode can be found on CISO Series.

    Troy Hunt's new site, "Dumb Password Rules," demonstrates yet another slice of security theater. Rules designed to make the creator believe they're making the business more secure, but appear to do nothing more than create unnecessary roadblocks and confusion.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Our guest is Dave Hannigan (@davidhannigan), CISO, Nubank.

    Thanks to our podcast sponsor, Reqfast

    Stop treating your various intelligence and security functions as if they are separate, unrelated activities and, instead, bring them together with Reqfast. Identify what's needed, identify areas for improvement, and make data-driven decisions with confidence.

    In this episode:

    • Are dumb password rules the result of security theater or limitations of old technology?
    • What really causes lack of sleep and burnout among IT and Security leaders?
    • Why are we still struggling with cybersecurity hiring?
    39 min
  • Make Them a Passwordless Offer They Can't Refuse (LIVE in Denver)

    This week's episode was recorded in front of a live audience at the Colorado Convention Center in Denver as we kicked off the Rocky Mountain Information Security Conference (RMISC). See the blog post for this episode here.

    Joining me, David Spark (@dspark), producer of CISO Series, on stage was my guest co-host, Jay Wilson, CISO for Insurity. Our guest is Michelle Wilson, CISO, Movement Mortgage.

    HUGE thanks to our sponsor, Trend Micro

    The stakes are high for cybersecurity decision makers as the threat landscape and attack surface continue to evolve. Explore Trend Micro's CISO Resource Center for research-driven strategic insights and best practices to help leaders better understand, communicate, and minimize cyber risk across the enterprise. Learn more.

    47 min
  • After a Breach, Security and Privacy Are Very Important to Us

    All links and images for this episode can be found on CISO Series.

    Why does it seem that the only time we hear about a company's concern about security and privacy is after they're compromised. It is only at that moment they feel compelled to let us know that they're taking this situation very seriously because as we've ll heard before "security and privacy are very important to us."

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Andrea Bergamini, CISO, Orbia.

    Thanks to our podcast sponsor, Varonis

    Everyday, your employees share thousands of sensitive files with too many people, exposing data to the entire organization – or even the entire internet. Varonis monitors sharing link activity and intelligently eliminates links that aren't needed – reducing your risk on a continual basis. Discover more at www.varonis.com/cisoseries.

    In this episode:

    • Why does it seem that the only time we hear about a company's concern about security and privacy is after they're compromised?
    • Is it only because at that moment they feel compelled to let us know that they're taking this situation very seriously?
    • How do you get things going before you have a massive breach?
    41 min
  • Your Lips Say "No," But I'm Not Listening

    All links and images for this episode can be found on CISO Series.

    There is a long history of security professionals complaining about the insecurity of new technologies. When new technologies take off, they rarely have lots of great security built in. The populace never comes around and says, "Security is right. We should stop using this thing we love." The popular technology ALWAYS wins.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Rinki Sethi (@rinkisethi), vp and CISO, BILL.

    Thanks to our podcast sponsor, OffSec

    With a Learn Enterprise plan, your employees get unlimited access to over 1,500 videos, 2,000 practical exercises, and more than 800 hands-on labs. The library is updated regularly with training content and modules defensive and offensive job role-specific content, from foundational to advanced. Google, Vmware, Microsoft all trust OffSec.

    In this episode:

    • Is it a coincidence that there is a long history of security professionals complaining about the insecurity of new technologies?
    • When new technologies take off, why do they rarely have lots of great security built in?
    • How does a cyber aware c-suite/board make better decisions that help a CISO and the business?
    39 min
  • Failure Is The Likely Option

    All links and images for this episode can be found on CISO Series.

    When cybersecurity needs to cut budget, first move is to look where you have redundancy. That way you're not actually reducing the security effort. But after that, the CFO needs to know what are the most important areas of the business to protect. Where will they be willing to take on more risk? Because, with less security, the chances of failure increase.

    This show was recorded in front of a live audience in New Orleans as part of the BSidesNOLA 2023 reboot conference. The episode features me, David Spark (@dspark), host and producer of CISO Series. My guest co-host is my former co-host, Allan Alford (@allanalfordintx), CISO for Precedent and host of The Cyber Ranch Podcast. Our guest is Mike Woods, corporate CISO for GE.

    Thanks to our podcast sponsors: Conveyor, Nightfall AI, Rapid7

    Love security questionnaires? Then you're going to hate Conveyor: the end-to-end trust platform built to eliminate questionnaires. Infosec teams reduce the volume of questionnaires with a customer-facing trust portal and for any remaining questionnaires, our GPT-Questionnaire Eliminator response tool or white-glove questionnaire completion service will knock them off your to-do list. www.conveyor.com

    Nightfall is the leader in cloud data leak prevention. Integrate in minutes with cloud apps such as Slack and Jira to instantly protect data (PII, PHI, Secrets and Keys, PCI) and prevent breaches. Stay compliant with frameworks such as ISO 27001 and more — all powered by Nightfall's industry-leading ML detection.

    Rapid7 is the only connected, cloud to on-prem cybersecurity partner with unlimited incident response, unlimited automated workflows, unlimited vulnerability management, unlimited app security, you get the idea. Add it up – with Rapid7's decades of practitioner-first problem solving – and there's unlimited opportunity for you. See for yourself at Rapid7.com/ciso-series.

    In this episode:

    • We always say, "trust but verify," but how do you actually verify?
    • When it comes to cut budget, make sure you're already in the mind of the CFO.
    • What's the difference between a good cybersecurity professional and a great one?
    46 min
  • A Fireman? A Princess? How About a CISO?

    All links and images for this episode can be found on CISO Series.

    As children, we don't dream of becoming a CISO, but yet we still have them. What is it a security professional can learn or even show, to demonstrate that they're getting ready for the position of a CISO?

    This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis, operating partner, YL Ventures. Our guest is Paul Connelly, former CISO, HCA Healthcare.

    Thanks to our podcast sponsor, Nightfall

    Nightfall is the leader in cloud data leak prevention. Integrate in minutes with cloud apps such as Slack and Jira to instantly protect data (PII, PHI, Secrets and Keys, PCI) and prevent breaches. Stay compliant with frameworks such as ISO 27001 and more — all powered by Nightfall's industry-leading ML detection.

    In this episode:

    • What is it a security professional can learn or even show, to demonstrate that they're getting ready for the position of a CISO?
    • How to tell that you are NOT CISO material?
    • What don't CISOs know about physical security that they should know before they get into big trouble?
    39 min

About CISO Series Podcast

From the publisher's feed

Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.

More shows like CISO Series Podcast

Hacked by Hacked

Hacked

193 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

374 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,064 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

180 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners

CISO Tradecraft® by G Mark Hardy & Ross Young

CISO Tradecraft®

48 Listeners

Security You Should Know by CISO Series

Security You Should Know

9 Listeners