CISO Series Podcast

CISO Series Podcast

By David Spark, Mike Johnson, and Andy EllisNewsTechnologyTech News
Download on the App Store

CISO Series Podcast episodes

  • We Want to Hire Honest People Who Think Like Criminals

    All links and images for this episode can be found on CISO Series

    What game should we play where we can trust you to behave fairly, but at the same time see how you could take advantage of us?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Deneen DiFiore (@deneendifiore), CISO, United Airlines.

    Thanks to our podcast sponsor, Code42

    As organizations gradually and cautiously move out of adapt out of adapt-or-die mode into the post-pandemic era, we can expect a second phase of digital transformation: resilience building. This presents an opportunity for security teams. An opportunity to re-imagine data security. More from Code42.

    In this episode:

    • Does becoming a business-minded security person take time?
    • What does a qualified, entry level candidate have to do to get noticed?
    • Without clear ROI, how does a CISO justify their budget?
    • What game taught you the most about thinking like a hacker?

    36 min
  • A Quick Way to Tell Which Vendors You Should Avoid

    All links and images for this episode can be found on CISO Series

    Do you really need hundreds of questions to know if you want to work with a vendor? Won't just two or three well-pointed questions really give you a good idea?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Nick Selby (@fuzztech), CSO, Paxos Trust Company and co-host of Tech Debt Burndown podcast.

    Thanks to our podcast sponsor, Kenna Security

    In this episode:

    • How do you suss out security vendors to make sure they're not a risk?
    • How do you battle a typosquatter?
    • What types of preparations do you have in place to know you're well prepared for an incident?
    • How should CISOs and CIOs share cybersecurity ownership?
    35 min
  • The Ostrich Approach To Vulnerability Management

    All links and images for this episode can be found on CISO Series

    OK, you showed us our vulnerability. But we really don't want to fix it now. Could we just pay you off to keep quiet, and to buy us some more time to deal with this in a "not so timely" manner?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Sameer Sait (@sameersait), CISO, Amazon - Whole Foods.

    Thanks to our podcast sponsor, Code42

    As organizations gradually and cautiously move out of adapt out of adapt-or-die mode into the post-pandemic era, we can expect a second phase of digital transformation: resilience building. This presents an opportunity for security teams. An opportunity to re-imagine data security. More from Code42.

    In this episode:

    • What if software developers used academic citations for code acquired from outside sources?
    • What is a reported security vulnerability doesn't get fixed? Where do you go next?
    • What if a 3rd party app developer needs access to a file/print share over the internet?
    • What if you receive a pitch that makes a grandiose statement like "no false positives?" Follow-up or hard pass?

    36 min
  • Sorry, We're Full. We Can't Take Any More Market Segments

    No, please not another acronym. I can't take another education cycle on another product segment. Oh, I'm sure Gartner is launching it. And I'm sure they'll make yet another Magic Quadrant to tell us which companies are in this new market segment. And we're going to have to buy this report so we understand this new category so we can create yet another line item on our budget sheet.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our sponsored guest is Ed Bellis (@ebellis), co-founder and CTO, Kenna Security (now a part of Cisco).

    Thanks to our podcast sponsor, Kenna Security

    In this episode:

    • How do you develop unbiased knowledge about a new technology?
    • Do you have advice on how to prepare for a SOC interview?
    • Vulnerability management: what have we heard enough of?
    • Do your parents know what you do for a living?

    37 min
  • What's the ROI of Nothing Happening?

    You don't want anything to happen, but you also want security to somehow to calculate ROI. Maybe the ROI could be calculated from actual sales that security allowed to actually happen.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our sponsored guest is Ryan Gurney, CISO-in-residence, YL Ventures.

    Thanks to our sponsor, YL Ventures

    YL Ventures, a global VC firm, manages over $300 million and exclusively invests in early-stage Israeli cybersecurity startups. YL Ventures accelerates the evolution of its portfolio companies via strategic advice and operational execution, leveraging a network of CISOs and industry veterans from Fortune 100 and high-growth companies.

    In this episode:

    • What happens when Application Surface Management (ASM) vendors are purchased as Security assets?
    • What do you do when your company wants to use a really insecure SaaS product?
    • Does a startup need a CISO, or just a CISO-in-residence?
    • Is there a better sign other than "nothing happened" that indicates you did a good job in cybersecurity today?"

    38 min
  • Could We Speak To Your CISO To Confirm He Received the Cupcakes?

    All links and images for this episode can be found on CISO Series

    It's imperative we speak to him. We want to make sure they landed safely. And if he has some available time, maybe we can show him our slide deck.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Branden Newman, svp, CISO, MGM Resorts.

    Thanks to our podcast sponsor, Grip Security

    Ask yourself – do I know what SaaS my company is using? How do users access them? What data is uploaded and downloaded? Enterprises today are using hundreds and thousands of different SaaS, and have lost control over it. Grip Security sees and secures every SaaS application. With simple deployment, you can have immediate visibility to the entire SaaS portfolio, and automated access and data governance at scale. This is the only way you could fight the SaaS Sprawl.

    In this episode:

    • How do security vendors communicate their uniqueness and product quality?
    • If you were to start a data security company - what gap would you fill?
    • What's the pushiest sales tactic you've seen in InfoSec?
    • Assessing vendor pitches on email security or human layer security

    41 min
  • Make Your Friends Jealous with Our Hand-Crafted Passwords

    All links and images for this episode can be found on CISO Series

    I know your friends say they use excellent passwords, but they don't take the time and care we put into choosing the right combination of letters, numbers, and special characters that's unique to your personality. Once your friends and the dark web have a chance to see them, they'll want to emulate you by using your password over and over again.

    This week's CISO/Security Vendor Relationship Podcast was actually recorded in front of a small live audience at The Passwordless Summit in Newport, Rhode Island. The event was sponsored by HYPR, our sponsor for this episode as well. Joining me and my co-host, Andy Ellis (@csoandy), operating partner, YL Ventures, was our sponsored guest, Brian Heemsoth (@bheemsoth), head of cyber defense and monitoring, Wells Fargo.

    Thanks to our podcast sponsor, HYPR

    HYPR is the leader in Passwordless Multi-factor Authentication. We protect workforce and customer identities with the highest level of assurance while enhancing the end user's experience. HYPR shifts the economics of attack to the enterprise's favor by replacing password-based MFA with Passwordless MFA. Welcome to The Passwordless Company®. It's time to reimagine Identity Access Assurance. Learn More »

    In this episode:

    • Ways to make a good impression about the quality of your security
    • How's passwordless access working for you?
    • When an EULA says no to reviewing the product
    • What does a good SOC look like to you?
    43 min
  • Are You Asking "How Secure Are We?" or "How Insecure Am I?"

    All links and images for this episode can be found on CISO Series

    We've heard the question "How secure are we?" many times, and we know what it really means.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Kevin Morrison, CISO, Alaska Air.

    Thanks to our podcast sponsor, Enso

    Enso, an Application Security Posture Management platform, helps security teams scale and gain control over their AppSec programs. Enso discovers application inventory, ownership and risk to easily build and enforce security policies and transform AppSec into an automated, systematic discipline.

    In this episode:

    • Red flag-level bad security: run away or offer to help?
    • How necessary is it to know patterns of where and how criminals are going to attack?
    • How to manage the risk of onboarding entry level cybersecurity personnel who lack prior job experience?
    • How do you answer the question, "Are we secure?"

    34 min
  • Tips to Finding an Incompetent Overpriced Cybersecurity Consultant

    All links and images for this episode can be found on CISO Series

    What questions should we be asking of a consultant's referrals to see if they're really worth the money they're trying to overcharge us?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Ira Winkler (@irawinkler), CISO, Skyline Technology Solutions.

    Thanks to our podcast sponsor, Varonis

    Varonis will help you get meaningful data security results faster than you thought possible. Protect sensitive data, detect sophisticated threats and streamline privacy and compliance. Visit varonis.com/risk for a demo of Varonis' leading data security platform.

    In this episode:

    • Fujifilm refused to pay ransomware demand, restored from backup. Be like Fujifilm.
    • What to do with people who ask for your password and sign-on – and those who comply
    • Best techniques for interviewing cybersecurity consultant candidates
    • The importance of securing inter-organization Slack and Teams channels
    34 min
  • We Shame Others Because We're So Right About Everything

    All links and images for this episode can be found on CISO Series

    You think it's easy carrying around the burden of being so perfect all the time? It's tough to carry that responsibility to tell others what they need to do.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Ed Contreras (@cisoedwardc), CISO, Frost Bank.

    Thanks to our podcast sponsor, Varonis

    Varonis will help you get meaningful data security results faster than you thought possible. Protect sensitive data, detect sophisticated threats and streamline privacy and compliance. Visit varonis.com/risk for a demo of Varonis' leading data security platform.

    • Does a quality tech stack help with recruitment and retention of talent?
    • Should security features be free?
    • And should those who charge be shamed?
    • Failing phishing tests - is there a limit to how many?
    36 min

About CISO Series Podcast

From the publisher's feed

Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.

More shows like CISO Series Podcast

Hacked by Hacked

Hacked

193 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

374 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,064 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

180 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners

CISO Tradecraft® by G Mark Hardy & Ross Young

CISO Tradecraft®

48 Listeners

Security You Should Know by CISO Series

Security You Should Know

9 Listeners