CISO Series Podcast

CISO Series Podcast

By David Spark, Mike Johnson, and Andy EllisNewsTechnologyTech News
Download on the App Store

CISO Series Podcast episodes

  • How to Be So Awesome CISOs Can't Ignore You

    All links and images for this episode can be found on CISO Series

    The trick to getting the attention of CISOs is to create an awesome company. Focus on that and the attention will follow.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Katie Stebbins (@ktlgs), board president, Global Epic.

    Thanks to our podcast sponsor, Kenna Security

    Kenna Security, now part of Cisco, is the pioneer of risk-based management. The Kenna Security Platform enables organizations to work cross-functionally to determine and remediate cyber risks. It leverages machine learning and data science to track and predict real-world exploitations, empowering security teams to focus on what matters most.

    In this episode:

    • So, how do you become so awesome that you can't be ignored?
    • What happens when you expand your view of the purpose of security metrics?
    • Is it possible to have a Digital Geneva Convention?
    33 min
  • Attract the Best Candidates with Crappy Benefits and Low Pay

    All links and images for this episode can be found on CISO Series

    If you're up against Google, Facebook, or Apple for hiring talent, chances are pretty good that your company is not going to match their pay and benefits. So if they're the bar for salary and benefits, your business' offerings will inevitably be subpar. So how do you build your employer brand to contend in areas where you're deficient in areas you can't compete?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our sponsored guest is Dan DeCloss (@wh33lhouse), CEO, PlexTrac.

    Thanks to our podcast sponsor, PlexTrac

    In this episode:

    • When setting up defenses against MITRE ATT&CK mappings, how much is enough?
    • What are you doing to build your employer brand and attract cyber talent to your business?
    • How should you review your pentest results?
    33 min
  • If the Network Is Up, Somebody Is Violating Our Acceptable Use Policy

    All links and images for this episode can be found on CISO Series

    Every organization has an Acceptable Use Policy (AUP) for their computers and network. Nobody reads it and everybody violates it. How the heck do you enforce or discipline people who violate your company's AUP?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our sponsored guest is Matt Radolec, senior director, incident response and cloud operations, Varonis.

    Thanks to our podcast sponsor, Varonis

    On average, an employee can access 17 million files on day one. Varonis will show you where critical data is vulnerable, detect anomalies, and automatically right-size privileges to get you to "Zero Trust." Their data security platform can test your ransomware readiness and show you where you stack up. Learn more at www.varonis.com/cisoseries.

    In this episode:

    • Why do tabletop exercises fail?
    • How should we deal with AUPs that do not get read?
    • Is cyber resiliency an overused term?
    • How valuable are visual detection techniques?
    37 min
  • What We Lack In Security We'll Make Up in School Spirit

    All links and images for this episode can be found on CISO Series

    Yikes, this security hole one concerned student found in the school's network is going to require one heck of a pep rally to fix.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Dave Stirling, CISO, Zions Bancorporation.

    Thanks to our podcast sponsor, Varonis

    On average, an employee can access 17 million files on day one. Varonis will show you where critical data is vulnerable, detect anomalies, and automatically right-size privileges to get you to "Zero Trust." Their data security platform can test your ransomware readiness and show you where you stack up. Learn more at www.varonis.com/cisoseries.

    In this episode:

    • Should the CISO position be seen as an organization in itself?
    • Is the current data loss prevention (DLP) model outdated?
    • How can an MSSP show its value?
    • What should a high school student do if they see that their school has horrible security practices?
    33 min
  • What's the Least Annoying Way to Follow Up with a CISO?

    All links and images for this episode can be found on CISO Series

    If we had such a great conversation at the conference, why don't you want to respond to my emails?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Julie Tsai (@446688), cybersecurity leader.

    Thanks to our podcast sponsor, Varonis

    What is your ransomware blast radius? The average user can access 17 million files. Varonis reduces your blast radius in days, not years. Combined with advanced detection that monitors every file touch, ransomware doesn't stand a chance. Get a free risk assessment.

    In this episode:

    • Is there a "right" management structure for cybersecurity?
    • Are there tools you can put in place to keep your DevOps program in check?
    • What are the questions to ask during an interview that reveal how a company handles and prioritizes cybersecurity?
    • How can we improve CISO / vendor relations?
    35 min
  • Why Ignoring Most of Your Vulnerabilities Is the Best Strategy

    All links and images for this episode can be found on CISO Series

    Winning at vulnerability management is not a numbers game. It's a tactical exercise of what matters most in your environment. Surprisingly, experts tell us close to two thirds of your vulnerabilities can and should be ignored. Why and which ones are those?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our sponsored guest is Ed Bellis (@ebellis), co-founder and CTO, Kenna Security (now a part of Cisco).

    Thanks to our podcast sponsor, Kenna Security

    Kenna Security, now part of Cisco, is the pioneer of risk-based management. The Kenna Security Platform enables organizations to work cross-functionally to determine and remediate cyber risks. It leverages machine learning and data science to track and predict real-world exploitations, empowering security teams to focus on what matters most.

    In this episode:

    • What type of risk or compliance data should CISA collect for its proposed metrics?
    • Which metrics are most valuable to determine the health of a company?
    • Why the constant frustration with patch management?
    • How often should you be conducting vulnerability scans?
    35 min
  • Why We Quickly Reject 95% of All Applicants

    All links and images for this episode can be found on CISO Series

    If you're asking what certification you should go after to get the perfect cybersecurity job, you're asking the wrong question. Most hiring managers are inundated with resumes so they're looking for ways to get rid of yours. Don't be fooled thinking you're going to be seen because you have the "perfect" resume.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Mike Hanley (@_mp4h), CSO, GitHub.

    Thanks to our podcast sponsor, BitSight

    These are challenging times for security professionals. From managing third party supply chain risk, to quantifying financial exposure, to reducing the likelihood of ransomware, BitSight helps security and risk professionals create more effective cybersecurity programs with cybersecurity ratings and analytics. Learn why Moody's, the Department of Defense, and other leading institutions partner with BitSight at www.bitsight.com

    In this episode:

    • What's the formula (experience vs testimonials) for hiring managers' attention?
    • What are the most effective techniques to building a resilient security team?
    • What are security vendors NOT doing now that would greatly improve their visibility?
    • Have you had to make any security exceptions just because an executive needed something?
    37 min
  • Security So Good Your Users Won't Use It

    All links and images for this episode can be found on CISO Series

    CISOs agree that multi-factor authentication is the one security control that once deployed has the greatest impact to reduce security issues. Yet with all that agreement, it's still so darn hard to get users to actually use it.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Arvind Raman (@arvind78), CISO, Mitel.

    Huge thanks to our sponsor, Horizon3.ai

    See your enterprise through the eyes of the attacker, identify your ineffective security controls, and ensure your limited resources are spent fixing problems that can actually be exploited. More from Horizon3.ai.

    In this episode:

    • If MFA is so great, why is it not more widespread?
    • Are high valuations for cloud security startups a vote against cloud providers doing cloud security well?
    • What is the biggest challenge in deploying zero trust on existing infrastructure?
    • Are there universal security red flags?
    36 min
  • We've Never Taken On So Much Risk

    All links and images for this episode can be found on CISO Series

    It's all risk, all show, for the entire show. It's just the kind of risk we like to take.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our sponsored guest is Derek Vadala (@derekvadala), chief risk officer, BitSight.

    Thanks to our podcast sponsor, BitSight

    These are challenging times for security professionals. From managing third party supply chain risk, to quantifying financial exposure, to reducing the likelihood of ransomware, BitSight helps security and risk professionals create more effective cybersecurity programs with cybersecurity ratings and analytics. Learn why Moody's, the Department of Defense, and other leading institutions partner with BitSight at www.bitsight.com

    In this episode:

    • What cybersecurity risk is currently the most severe?
    • What's important about of evaluating a startup's security protocols?
    • What about third party risk management?
    • Do you and your board know how resilient you are to a cyber attack?
    36 min
  • The Perfect Gift for a Cyber Crook

    All links and images for this episode can be found on CISO Series

    What do you give to the person who wants to learn how to steal everything?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our sponsored guest Jim Wachhaus (@imanapt), risk intelligence evangelist, CyCognito.

    Thanks to our podcast sponsor, CyCognito

    By understanding risks, attacks, and behaviors from attack surface management data, CyCognito visualizes the pathways attackers will take to exploit your network enabling you the ability to see, understand and eradicate the threat. CyCognito is the only cyber risk intelligence platform that visualizes the attackers paths into your network.

    In this episode:

    • How can we shore up our cybersecurity hygiene?
    • What have we heard enough about with risk intelligence ?
    • Gifts to buy someone who is looking into red teaming/vulnerability

    34 min

About CISO Series Podcast

From the publisher's feed

Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.

More shows like CISO Series Podcast

Hacked by Hacked

Hacked

193 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

374 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,064 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

180 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners

CISO Tradecraftยฎ by G Mark Hardy & Ross Young

CISO Tradecraftยฎ

48 Listeners

Security You Should Know by CISO Series

Security You Should Know

9 Listeners