CISO Series Podcast

CISO Series Podcast

By David Spark, Mike Johnson, and Andy EllisNewsTechnologyTech News
Download on the App Store

CISO Series Podcast episodes

  • A Look Back at Foolish Security Policies of Past and Present

    All links and images for this episode can be found on CISO Series

    Are bad security policies of yesteryear just because we didn't know any better at the time, or were they some bozos idea of legitimate security yet the rest of us knew it was just security theater?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Dr. Diane M Janosek (@dm_janosek), deputy director of compliance, NSA and senior legal advisor for Women in Cybersecurity.

    Thanks to our podcast sponsor, Code42

    As the Insider Risk Management leader, Code42 helps security professionals protect corporate data and reduce insider risk while fostering an open and collaborative culture for employees. For security practitioners, it means speed to detection and response. For companies, it means a collaborative workforce that is productive and a business that is secure. Visit http://Code42.com/showme to learn more.

    In this episode:

    • We highlight obsolete security policies to steer clear of.
    • We examine security in space and how can others who are not directly involved in these industries create some type of positive impact?
    • And we ask how we can improve inclusion by decrypting the lack of diversity in our industry.
    40 min
  • Decommission Our Legacy Tech or Just Shut Down the Business?

    All links and images for this episode can be found on CISO Series

    Legacy tech can often be the anchor that prevents an organization from growing. Put the issue of dealing with legacy tech long enough and the problem could get bigger than the business itself.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is TJ Mann (@teejaymann), CISO, Children's Mercy Kansas City.

    Thanks to our podcast sponsor, CYREBRO

    Ninety percent of post mortems show that the high cost of damage from a cyberattack was avoidable, but no one knew in time to stop it. CYREBRO's SOC Platform is your cybersecurity central command, integrating all your security events with 24/7 strategic monitoring, proactive threat intelligence, and rapid incident response. More from CYREBRO.

    In this episode:

    • How legacy technology impedes business agility?
    • Are we doing anything better to deal with legacy technology
    • Is there anything that can be done at the purchase point to understand how you'll sunset equipment and technology
    • And we ask whether or not our industry is willing to take the time and effort to hire and train the talent they so desperately want and need.
    38 min
  • Life's Certainties: Death, Taxes, and Violating Security Policies

    All links and images for this episode can be found on CISO Series

    People violate cybersecurity policies at a rate of one out of every 20 job tasks. It's just a matter of time before all your employees are in violation.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Bruce Schneier (@schneierblog), chief of security architecture, Inrupt and fellow and lecturer and Harvard Kennedy School.

    Thanks to our podcast sponsor, PlexTrac

    PlexTrac is a powerful, yet simple, cybersecurity platform that centralizes all security assessments, pentest reports, audit findings, and vulnerabilities. PlexTrac transforms the risk management lifecycle, allowing security professionals to generate better reports faster, aggregate and visualize analytics, and collaborate on remediation in real-time.

    Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!

    In this episode:

    • Special tips for new CISOs just starting out and trying to establish their position.
    • We examine where there are market forces fighting the most against achieving societal values in the digital space?
    • What are signs that we're moving in the right direction of developing a digital social contract?
    • And we ask, is "employees violating security policies" the top issue that needs to be resolved?
    34 min
  • Is It a Promotion or a Red Flag Telling You To Get Out?

    All links and images for this episode can be found on CISO Series

    A young woman is killing it in her first cybersecurity job out of college. Management is so thrilled with her that they want to give her a promotion. Problem is the promotion reveals a lot of other innerworkings that don't speak well of the company's culture.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Davi Ottenheimer (@daviottenheimer), vp trust and digital ethics, Inrupt.

    Thanks to our podcast sponsor, Code42

    As the Insider Risk Management leader, Code42 helps security professionals protect corporate data and reduce insider risk while fostering an open and collaborative culture for employees. For security practitioners, it means speed to detection and response. For companies, it means a collaborative workforce that is productive and a business that is secure. Visit http://Code42.com/showme to learn more.

    In this episode:

    • A student has some serious privacy concerns when they learn that "all data is being monitored and anonymously collected."
    • We examine how we can break from the Internet Oligarchs who appear to be consuming, selling, and using so much of our data.
    • How GDPR can benefit organizations to stay ahead of the competition.
    • A young recruit facing imposter syndrome after receiving a promotion with added responsibilities.
    40 min
  • It's a Great Job, But I'm Alone and Terrified

    All links and images for this episode can be found on CISO Series

    First job out of college and you get the cybersecurity job of your dreams... and nightmares. It's just too much, and you definitely don't have the experience to handle it all.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Rick Doten (@rick_doten), CISO, Carolina Complete Health.

    Check out Rick's Youtube channel with the CIS Critical Security Control videos.

    Thanks to our podcast sponsor, Kenna Security

    Kenna Security, now part of Cisco, is the pioneer of risk-based management. The Kenna Security Platform enables organizations to work cross-functionally to determine and remediate cyber risks. It leverages machine learning and data science to track and predict real-world exploitations, empowering security teams to focus on what matters most.

    In this episode:

    • We look at the #1 job according to a U.S. News & World Report. Hint: It's Information Security Analyst.
    • We examine the possibility & practicality of running a security program entirely based upon free and open-source software.
    • We break down how to help brand new recruits on the ground as they start their careers in cybersecurity.
    37 min
  • Instead of Increased Cybersecurity, Could We Just Order Less Risk?
    All links and images for this episode can be found on CISO Series

    "No business wants more security, they want less risk," said a redditor on the cybersecurity subreddit. Executives seem to not care about cybersecurity because they're not talking in those terms. They talk in terms of managing risk. It's the InfoSec professional's job to do the translation.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Tom Doughty, vp and CISO, Prudential Financial.

    Thanks to our podcast sponsor, CYREBRO

    Ninety percnet of post mortems show that the high cost of damage from a cyberattack was avoidable, but no one knew in time to stop it. CYREBRO's SOC Platform is your cybersecurity central command, integrating all your security events with 24/7 strategic monitoring, proactive threat intelligence, and rapid incident response. More from CYREBRO.

    In this episode:

    • How do you discuss cybersecurity with executives who don't care about cybersecurity?
    • Does cybersecurity insurance help motivate better cybersecurity awareness?
    • Why are we still struggling with cybersecurity hiring?
    • What does a great day in information security look like?
    36 min
  • Why CISOs Avoid the Dreaded "Request a Demo" Button

    All links and images for this episode can be found on CISO Series

    A CISO hears about your company's product from some other CISOs. Eager to find more information like a video demo they could watch on their own, they visit your site. They can't find anything except a prominently placed "Request a Demo" button. Fearing the marketing and salespeople who will hound them if they fill out the information, they just bail.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Jim Routh (@jmrouth1), former CISO for MassMutual and CVS/Aetna.

    Thanks to our podcast sponsor, Buchanan Technologies

    Short staffed and overworked IT groups can be overwhelmed by the massive scope of a comprehensive cybersecurity program. Buchanan Technologies makes the complex simple with our twenty-four by seven, customized, vetted strategies that identify risks, detect threats, implement security controls, and protect the confidentiality, availability, and integrity of your data. Discover more.

    In this episode:

    • Why do vendors put the product demo videos behind gated walls?
    • Tips for improving cybersecurity awareness within a large organization.
    • The annoying pains of the vendor ecosystem.
    • What are some really bad cybersecurity practices that need to be corrected right away?
    40 min
  • What's Next in Cybersecurity? Look at Last Year and Expect More

    All links and images for this episode can be found on CISO Series

    The web is awash with sites claiming they know what the security trends will be for 2022. All of them were filled with quotes from security experts at different vendors who "surprise" we're saying the big trend is what their product can fix. One publication, eWEEK, had probably the only logical set of trends and they look a lot like what happened in 2021.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our sponsored guest is Ori Arbel, CTO, CYREBRO.

    Thanks to our podcast sponsor, CYREBRO

    Ninety percent of post mortems show that the high cost of damage from a cyberattack was avoidable, but no one knew in time to stop it. CYREBRO's SOC Platform is your cybersecurity central command, integrating all your security events with 24/7 strategic monitoring, proactive threat intelligence, and rapid incident response. More from CYREBRO.

    In this episode:

    • How should you be handling your security operations center (SOC)?
    • Tips for improving your incident response planning.
    • What are the cloud security trends of 2022?
    34 min
  • Are You Attending the "What to Worry About Next" Security Conference?

    All links and images for this episode can be found on CISO Series

    Are security conferences really helpful in advising you on making your business more secure, or are they just adding more worries to your plate that aren't actually going to be threats your business is going to have to face?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Jason Witty, CSO, USAA.

    Thanks to our podcast sponsor, CyCognito

    By understanding risks, attacks, and behaviors from attack surface management data, CyCognito visualizes the pathways attackers will take to exploit your network enabling you the ability to see, understand and eradicate the threat. CyCognito is the only cyber risk intelligence platform that visualizes the attackers paths into your network.

    In this episode:

    • What is the board's risk appetite?
    • Is attending conferences helpful?
    • What can security vendors do to help with board-level communications?
    36 min
  • It's BAAAACK! The Return of "We Could Have Stopped That Breach"

    All links and images for this episode can be found on CISO Series

    Our entire network launched because of the irritation CISOs had with vendors could have stopped some breach that happened to another company. Then the chest pounding subsided, and we thought we were making an impact, until Log4j appeared...

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Tim Rohrbaugh, CISO, JetBlue.

    Thanks to our sponsor, CyCognito

    By understanding risks, attacks, and behaviors from attack surface management data, CyCognito visualizes the pathways attackers will take to exploit your network enabling you the ability to see, understand and eradicate the threat. CyCognito is the only cyber risk intelligence platform that visualizes the attackers paths into your network.

    In this episode:

    • Questionable vendor marketing tactics
    • Developing your threat intelligence
    • Valuable skills that hiring managers look for
    35 min

About CISO Series Podcast

From the publisher's feed

Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.

More shows like CISO Series Podcast

Hacked by Hacked

Hacked

193 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

374 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,064 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

180 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners

CISO Tradecraftยฎ by G Mark Hardy & Ross Young

CISO Tradecraftยฎ

48 Listeners

Security You Should Know by CISO Series

Security You Should Know

9 Listeners