CISO Series Podcast

CISO Series Podcast

By David Spark, Mike Johnson, and Andy EllisNewsTechnologyTech News
Download on the App Store

CISO Series Podcast episodes

  • How to Be a Security Vendor CISOs Can't Ignore

    All links and images for this episode can be found on CISO Series

    There are vendors that CISOs can't look away from. Who are they and what did they do to get so much attention from CISOs?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Saša Zdjelar, svp, security assurance, Salesforce.

    Thanks to our podcast sponsor, Sysdig

    Sysdig is driving the standard for cloud and container security. With Sysdig, teams find and prioritize software vulnerabilities, detect and respond to threats, and manage cloud configurations, permissions and compliance. Customers get a single view of risk from source to run, with no blind spots, no guesswork, no black boxes.

    In this episode:

    • What's a great approach from a security vendor?
    • What techniques do CISOs deploy to cut through the marketing noise?
    • Can you think of vendors that were so good that you couldn't ignore them. What made them achieve that status?
    42 min
  • I Pity the Fool Who Builds a Homogeneous Cyber A-Team

    All links and images for this episode can be found on CISO Series

    If you want to build a successful cybersecurity team, you need to be diverse, mostly in thought. But that diversity in thought usually is the result of people with diverse backgrounds who have had different experiences and have solved problems differently. It's actually really hard to hire a diverse team because what you want to do is simply hire people who look, talk, and sound like you. People who come from the same background as you. While that may work for building friends, it's not necessarily the best solution when building a team to secure your company.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is George Finney (@wellawaresecure), CISO, Southern Methodist University and author of "Well Aware: The Nine Cybersecurity Habits to Protect Your Future" and "Project Zero Trust."

    Thanks to our podcast sponsor, Feroot

    Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers. Our automated, client-side, data protection capabilities increase web application visibility, facilitate threat analysis, and detect and protect from client-side attacks, such as Magecart, XSS, e-skimming, and other threats focused on front-end web applications.

    In this episode:

    • What are the personality types you need on your staff?
    • Can you be a vCISO if you're not a CISO first. And if you're a vCISO without ever being a CISO, are you just a cybersecurity consultant?
    • Also, what are some creative uses of honeypots most users don't consider?
    37 min
  • The Cybersecurity Hamster Wheel of Getting Nothing Done

    All links and images for this episode can be found on CISO Series

    What are signs your team is getting burnt out? It's not an imbalance of work and family, it's feeling you're having no impact. That you're working your tail off and nothing is getting accomplished. This happens often in cybersecurity.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Sara-Michele Lazarus, vp/head of trust and security, Stavvy.

    Thanks to our podcast sponsor, Sysdig

    Sysdig is driving the standard for cloud and container security. With Sysdig, teams find and prioritize software vulnerabilities, detect and respond to threats, and manage cloud configurations, permissions and compliance. Customers get a single view of risk from source to run, with no blind spots, no guesswork, no black boxes.

    In this episode:

    • What are signs your team is getting burnt out?
    • What's the most valuable skill in a cybersecurity analyst?
    • Why are we seeing so many zero day exploits right now?
    41 min
  • Who Do You Need to Trust When You Build a Zero Trust Architecture?

    All links and images for this episode can be found on CISO Series

    Uggh, just saying "zero trust" sends shivvers down security professionals' spines. The term is fraught with so many misnomers. The most important is who are you going to trust to actually help you build that darn zero trust program? Are you going to look at a vendor that's consolidated solutions and has built programs like this repeatedly or are you going to look for the best solutions yourself and try to figure out how best to piece it together to create that "zero trust" program?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our sponsored guest is David Chow, global chief technology strategy officer, Trend Micro.

    Thanks to our podcast sponsor, Trend Micro

    Trend Micro Cloud One, a security services platform for cloud builders, delivers the broadest and deepest cloud security offering in one solution, enabling you to secure your cloud infrastructure with clarity and simplicity. Discover your dynamic attack surface, assess your risk, and respond with the right security at the right time. Discover more!

    In this episode:

    • Why is the term "zero trust" fraught with so many misnomers?
    • Is there such a thing as privacy anymore? Do you agree with the term "good enough", and if so what is a "good enough" factor, what does it entail, and what should we expect from that?
    • Where has the United States done the most to improve national cybersecurity?
    38 min
  • The Best Interview Questions and the Answers You Want to Run From

    All links and images for this episode can be found on CISO Series.

    You want an awesome job in cybersecurity, and you want to ask the right questions. What are the right answers, and which ones are red flags that should cause you to run?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Renee Guttman, former CISO, Campbell's, Coca-Cola, and Time Warner.

    Thanks to our podcast sponsor, Okta

    Auth0 is the leading provider of customer identity solutions. Watch Jameeka Aaaron, CISO for Auth0, explain how to balance security with friction to create a safe authentication experience without compromising on privacy.

    In this episode:

    • When interviewing, what are the right answers, and which ones are red flags that should cause you to run?
    • Has the cloud just created a bigger security problem that's creeped up on us?
    • Are legacy systems just a ticking time bomb or have you seen success in managing them?
    33 min
  • But I Spent All This Money. Why Are You Still Ignoring Me?

    All links and images for this episode can be found on CISO Series

    Are RSA and other big conferences worth it? It seems that fewer CISOs are actually walk the floor at these big trade shows. The really big meetings are happening outside of the conference. Why would CISOs attend these big conferences with airfares costing over $1000 and hotel rooms costing $500 to $800 a night? Are the customers and vendors getting priced out?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Jessica Ferguson, CISO, DocuSign.

    Thanks to our podcast sponsor, SlashNext

    SlashNext protects the modern workforce from phishing and human hacking across all digital channels. SlashNext Complete™ utilizes our patented AI SEER™ technology to detect zero-hour phishing threats by performing dynamic run-time analysis on billions of URLs a day through virtual browsers and machine learning. Take advantage of SlashNext's phishing defense services for email, browser, mobile, and API.

    In this episode:

    • Are big conferences like RSA worth it? What's the value of the trade show floor at RSA?
    • Why would CISOs attend these big conferences with airfares costing over $1000 and hotel rooms costing $500 to $800 a night?
    • Are the customers and vendors getting priced out?
    38 min
  • It's OK to Look Like a Cyber Hero. Just Don't Act Like One.

    All links and images for this episode can be found on CISO Series

    Security professionals should turn in the cyber hero mentality for the "sidekick" role. Many cybersecurity leaders believe they need to save the company from all the stupid users who can't protect themselves. The reality is security professionals should lose the saviour mentality for a supporting role where they're running alongside different business units trying to find a way to make their process run smoother and more secure.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our wponsored guest Clyde Williamson, product management, innovations, Protegrity.

    Thanks to our podcast sponsor, Protegrity

    Protegrity empowers intelligence-driven organizations to use data to drive innovation with secure analytics and artificial intelligence, without fear of violating compliance or jeopardizing privacy. To make this vision a reality, we protect sensitive data anywhere and everywhere to create secure data agility that aligns with the speed of modern business.

    In this episode:

    • Is it OK if users see security as heroes but security professionals shouldn't see themselves that way?
    • What have you heard enough about when it comes to data protection, and what would you like to hear a lot more?
    • How can we best create a cyber risk balance sheet?
    40 min
  • How to Market "Zero Trust" Without Making CISOs Cringe

    All links and images for this episode can be found on CISO Series

    Just the words "zero trust" often causes security professionals to shiver. In general, CISOs are on board with the concepts of "zero trust," we just think they're uncomfortable with how it's being used for branding and marketing efforts.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is David Cross (@mrdbcross), SVP/CISO for Oracle SaaS Cloud.

    Thanks to our podcast sponsor, Protegrity

    Protegrity empowers intelligence-driven organizations to use data to drive innovation with secure analytics and artificial intelligence, without fear of violating compliance or jeopardizing privacy. To make this vision a reality, we protect sensitive data anywhere and everywhere to create secure data agility that aligns with the speed of modern business.

    In this episode:

    • Should certifications be a requirement on your job listings?
    • Are the SIEMs failing or do the users not know how to configure them? Or is it both?
    • Why do security professionals treat the term "zero trust" so negatively? How should vendors approach zero trust and how should the C-suite understand it?
    34 min
  • When Good Decisions Go Bad

    All links and images for this episode can be found on CISO Series

    You can make the right decision given the information you have, but everything is a risk, so there are times those good decisions are going to result in not the result you were hoping for. In essence, plenty of good decisions result in poor outcomes.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Aviv Grafi, founder and CTO, Votiro and winner of season one of Capture the CISO.

    In this episode:

    • We welcome the winner of "Capture The CISO!" How did they prepare in terms of making the demo and for appearing on the show? And what advice would they give for contestants in season 2?
    • What do employers look for or ask in an interview that would lead them to hire and promote someone into a CISO role in their company?
    • How can cybersecurity professionals improve their decision making over time?
    40 min
  • When Does an Exaggeration Become a Lie?

    All links and images for this episode can be found on CISO Series

    We explore the world of dishonesty in cybersecurity. Practitioners know that marketers will stretch the truth, but how far are we willing to let that go? Isn't this industry built on trust? Can cybersecurity continue to thrive if we can't trust each other?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our sponsored guest is Anna Belak (@aabelak), director of thought leadership, Sysdig.

    Thanks to our podcast sponsor, Sysdig

    Sysdig is driving the standard for cloud and container security. With Sysdig, teams find and prioritize software vulnerabilities, detect and respond to threats, and manage cloud configurations, permissions and compliance. Customers get a single view of risk from source to run, with no blind spots, no guesswork, no black boxes.

    In this episode:

    • What are the questions a CISO should be able to answer?
    • How much dishonesty do you find in cybersecurity?
    • How does one LEAD a cloud migration?
    • What are some lies about machine learning that everyone needs to be aware of?
    39 min

About CISO Series Podcast

From the publisher's feed

Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.

More shows like CISO Series Podcast

Hacked by Hacked

Hacked

193 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

374 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,064 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

180 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners

CISO Tradecraft® by G Mark Hardy & Ross Young

CISO Tradecraft®

48 Listeners

Security You Should Know by CISO Series

Security You Should Know

9 Listeners