CISO Series Podcast

CISO Series Podcast

By David Spark, Mike Johnson, and Andy EllisNewsTechnologyTech News
Download on the App Store

CISO Series Podcast episodes

  • "I Love Being Monitored Online," Said No Employee Ever

    All links and images for this episode can be found on CISO Series

    What do you do if your boss gave you a corporate laptop and you fear they installed some tracking software? Should you wipe the drive or simply quit?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our sponsored guest is Purandar Das (@dasgp), co-founder and president, Sotero.

    Thanks to our podcast sponsor, Sotero

    Today's compliance requirements require a security mindset that focuses on the data itself. We can't truly protect sensitive data when our solutions only provide protection at the network, application or database level. The good news is that you can now protect the actual data itself. Click to learn how.

    In this episode:

    • Did the pandemic lead to innovations in cybersecurity?
    • What should a company do when an employee makes a major mistake like emailing PII?
    • Have we all heard enough about encryption?
    • What do we do when the boss gives us a "new" computer with monitoring tech on board?
    35 min
  • If We Don't Talk About Cyber Risk, Will It Go Away?

    All links and images for this episode can be found on CISO Series

    Risk is scary. Cyber risk is scarier. Not because it's worse, but mostly because we barely understand it. We've gone this long not understanding it. Maybe just ignoring it will allow us to wish it away.

    On this week's episode of CISO/Security Vendor Relationship Podcast we have our first in-studio guest (since we moved the studio). Joining me, David Spark (@dspark), producer of CISO Series and Mike Johnson is our in-studio guest TJ Lingenfelter (@tj_555), sr. program manager, information security, Taylormade Golf.

    Thanks to our podcast sponsor, BitSight

    These are challenging times for security professionals. From managing third party supply chain risk, to quantifying financial exposure, to reducing the likelihood of ransomware, BitSight helps security and risk professionals create more effective cybersecurity programs with cybersecurity ratings and analytics. Learn why Moody's, the Department of Defense, and other leading institutions partner with BitSight at www.bitsight.com

    In this episode:

    • How can competitive companies can help each other be more secure?
    • What to do when you can't get time with your CIO to discuss plans?
    • Are we fooling ourselves to think we can maintain privacy for ourselves and that organizations can do it for us as well?
    • What new cybersecurity buzzwords should be put to rest?

    36 min
  • After a Breach It's Really Easy to Calculate Risk

    All links and images for this episode can be found on CISO Series

    There's no question calculating risk is tricky. Because once you understand your risk then you can assign budget appropriately to reduce your risk. OR, you could just wait until you're breached and you'll know exactly what your risk is and how much it costs.

    This week's episode of CISO/Security Vendor Relationship Podcast is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Dan Walsh, CISO, VillageMD.

    Thanks to our podcast sponsor, deepwatch

    Increasing ransomware attacks and their evolving sophistication have been putting more pressure on security teams than ever before. Luckily, managed detection and response (or MDR) has emerged as a critical component for improving security operations, reducing ransomware risk, and minimizing the overall impact an attack can have. Visit deepwatch.com to see how we help to prevent breaches for our customers, by working together.

    In this episode:

    • What can we learn from a 10-year cybersecurity veteran?
    • What can state governments do to 'hire better' in cybersecurity?
    • What can companies do to attract cybersecurity professionals to their location?
    • What are ways to bring a clearer understanding of risk to the business without being alarmist?

    37 min
  • I've Got Zero Trust In My Understanding of Zero Trust

    All links and images for this episode can be found on CISO Series

    Don't look at me to explain zero trust to you, because I'm just as confused. I've heard plenty of definitions, and they all sound good. I just don't know which one is right, or maybe they're all right.

    This week's episode of CISO/Security Vendor Relationship Podcast was recorded in front of a live audience at KeyConf at the City Winery in New York City. My guest co-host for this special episode is JJ Agha, CISO, Compass. Joining us on stage were a host of guests, Admiral Rogers, former NSA director and Commander US Cyber Command, Oded Hareven, CEO and co-founder, Akeyless, and Dr. Zero Trust, Chase Cunningham (@cynjaChaseC).

    Thanks to our podcast sponsor, Akeyless

    As organizations embrace automation, they must control their secrets sprawl. Security teams must enable the transition with centralized access to secrets, and consistent policies to limit risk and maintain compliance. Akeyless provides a unified, SaaS based solution for Secrets Management, Secure Remote Access, and Data Protection. More about Akeyless

    In this episode:

    • Is zero trust easy for organizations to deploy and control?
    • Are we taking zero trust too far?
    • Does it help to have more eyes on the problem?
    • What are the problems with secure remote access that we're still struggling with?
    47 min
  • We're Very Good at SAYING We Care About Diversity

    All links and images for this episode can be found on CISO Series

    It's extremely easy to say you want to diversify. In fact, I'll do it right now three times. We want diversity. We're very pro diversity and it's our focus for the next year. Diversity is a very important part of our security program.

    Please don't ask to though look at the lack of diversity on our staff. It doesn't match our rhetoric.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Sujeet Bambawale (@sujeet), CISO, 7-11.

    Thanks to our podcast sponsor, Vulcan Cyber

    Vulnerability scanners are commoditized. Cloud service providers provide free scanners. Open source scanners are plentiful. Your team doesn't need another scanner, but they need to get better at identifying and prioritizing the risk that is buried in that scan data. Attend the Vulcan Cyber virtual user conference and learn how to assess and mitigate risk across all of your surfaces. Go to vulcan.io and click the button at the top of the screen to register for the event.

    In this episode:

    • How are you overcoming the challenges of diversity hiring?
    • Are robocalls defeating MFA?
    • Are you collaborative in cyber with your direct competitors?
    • Were you sold something differently when you started in cyber?

    39 min
  • Chances Are We'll Be Attacked the Day Before Your Vacation

    All links and images for this episode can be found on CISO Series

    Do the cybercriminals know my vacation schedule? If they're already in our network, they probably do. Why don't they share their vacation schedule with me. That way we can all enjoy our time off.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Patti Titus (@rusecur), CISO, Markel.

    Thanks to our podcast sponsor, Sotero

    Today's compliance requirements require a security mindset that focuses on the data itself. We can't truly protect sensitive data when our solutions only provide protection at the network, application or database level. The good news is that you can now protect the actual data itself. Click to learn how.

    In this episode:

    • What role is the quickest to a CISO role?
    • How can we best correlate security behavior to business actions?
    • Are attacks more likely on Fridays, just before a long weekend or vacation?
    • Which breaches this year caused a shift in focus of your security program?

    38 min
  • Did You Get My Last Email? This One Has a Joke In It.

    All links and images for this episode can be found on CISO Series

    At one point a sales representative will get so desperate trying to get a reply from a prospect that they'll resort to some tepid attempt a humor. We've all seen the email that is trying to understand why we're not replying. And the salesperson tries to make it easy for the recipient to respond by just pressing a single digit. 1: You're too busy, 2: You didn't see my email, 3: You really wanted to respond but you're stuck in a well.

    This week's episode of CISO/Security Vendor Relationship Podcast was recorded in front of a live audience at the SF-ISACA conference in San Francisco. It features me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is my other co-host Andy Ellis (@csoandy), operating partner, YL Ventures.

    Huge thanks to our podcast sponsors, Code42, Sotero, and Constella Intelligence

    As organizations gradually and cautiously move out of adapt-or-die mode into the post-pandemic era, we can expect a second phase of digital transformation: resilience building. This presents an opportunity for security teams. An opportunity to re-imagine data security. More from Code42.

    Today's compliance requirements require a security mindset that focuses on the data itself. We can't truly protect sensitive data when our solutions only provide protection at the network, application or database level. The good news is that you can now protect the actual data itself. Click to learn how.

    Threat actors target key employees due to their privileged access to sensitive data which can lead to credential theft, ATO, & ransomware attacks. Find out if your key employees and company have been exposed – without any obligation. More from Constella Intelligence.

    In this episode:

    • How do you go about making a business case for further investment in cyber security initiatives?
    • Is it possible to get people to get security people change their behaviors?
    • Using humor in cold sales. Does it ever work?
    • ...and what happens when it backfires?

    51 min
  • Hackers of the World Unite… When We Can Agree on a Time

    All links and images for this episode can be found on CISO Series

    "Look, you wanna be elite? You have to do a righteous hack."

    This entire episode we pay tribute to the movie "Hackers" with quotes all throughout the programming. This episode is hosted by me, David Spark (@dspark), producer of CISO Series, and my guest co-host Roland Cloutier (@CSORoland), CISO, TikTok. Joining us in this discussion is Steve Tran (@steveishacking), CISO, MGM Studios.

    Thanks to our podcast sponsor, Code42

    In this episode:

    • Is it time to start thinking about protecting data differently?
    • What is the biggest scam in tech that is deemed acceptable?
    • Why is the convergence of security between physical and digital still not happening?
    • Which part of your role is science vs art?
    38 min
  • Is Our CISO Doing a Good Job? Our CISO Doesn't Even Know.

    All links and images for this episode can be found on CISO Series

    It's extremely hard to tell if a cybersecurity leader is doing a good job. In fact, it's tough for even them to know. Our best bet is watching for an improvement in the cybersecurity program over time.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our sponsored guest is Mark Wojtasiak (@markwojtasiak), vice president, research & strategy, Code42 and co-author of "Inside Jobs."

    Thanks to this week's podcast sponsor, Code42

    As organizations gradually and cautiously move out of adapt out of adapt-or-die mode into the post-pandemic era, we can expect a second phase of digital transformation: resilience building. This presents an opportunity for security teams. An opportunity to re-imagine data security. More from Code42.

    In this episode:

    • What is your business's biggest frustration when managing cybersecurity?
    • Aaaand...what is your biggest frustration when managing cybersecurity?
    • How do you know when a Security Leader (including yourself) is doing a good job?
    • Would it help if Security hired a marketing manager?

    36 min
  • BONUS Episode: Innovation Spotlight

    Here's an awesome bonus episode of CISO/Security Vendor Relationship Podcast featured as the closing event at Evanta's Global CISO Virtual Executive Summit.

    Here's what went down. The day before our recording, three representatives presented their unique and innovative security solutions to a panel of CISOs and the virtual audience in attendance.

    The next day, everyone came back to offer up a quick elevator pitch and to be grilled by the CISOs. That's exactly what you get to hear on this bonus episode of CISO/Security Vendor Relationship Podcast.

    Thanks to all our sponsors for this bonus episode of the podcast

    Kasada

    Axis Security

    Ordr

    Ten Eleven Ventures

    42 min

About CISO Series Podcast

From the publisher's feed

Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.

More shows like CISO Series Podcast

Hacked by Hacked

Hacked

193 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

374 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,064 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

180 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners

CISO Tradecraft® by G Mark Hardy & Ross Young

CISO Tradecraft®

48 Listeners

Security You Should Know by CISO Series

Security You Should Know

9 Listeners