CISO Series Podcast

CISO Series Podcast

By David Spark, Mike Johnson, and Andy EllisNewsTechnologyTech News
Download on the App Store

CISO Series Podcast episodes

  • Will You Accept "My Bad" As Our Breach Response?

    All links and images for this episode can be found on CISO Series

    We know we've got to say something about this breach, but geez, the details are really sordid and it would just be easier if we could just wrap it up with one giant "oops." You cool with that?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our sponsored guest is Matt Radolec, senior director, incident response and cloud operations, Varonis.

    Thanks to our podcast sponsor, Varonis

    Varonis will help you get meaningful data security results faster than you thought possible. Protect sensitive data, detect sophisticated threats and streamline privacy and compliance. Visit varonis.com/risk for a demo of Varonis' leading data security platform.

    In this episode:

    • How have insider threats morphed since the onset of Covid?
    • Should paying ransomware be illegal?
    • What goes into a good post-breach public incident response?
    • Should ransomware focus more on backups?
    33 min
  • I'll Show You My Risk Profile If You Show Me Yours

    All links and images for this episode can be found on CISO Series

    Managing my own risk is tough enough, but now I have to worry about my partners' risk and their partners' risk? I don't even know what's easier to manage: the risk profile of all my third parties or all the exclusions I've got to open up to let third parties into my system.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our sponsored guest is Bruce Potter (@gdead), CISO, Expel.

    Thanks to our podcast sponsor, Expel

    Expel offers companies of all shapes and sizes the capabilities of a modern Security Operations Center without the cost and headache of managing one.

    In this episode:

    • What's easier to manage, 3rd party risk profiles or exclusions?
    • Do you need a Git repository to apply for a job? What else?
    • What's in your happy-grab-bag for hybrid work environments?
    • Is there anything new to say about ransomware strategy?
    35 min
  • How Much Charisma Do I Need to Push My Team to the Edge?

    All links and images for this episode can be found on CISO Series

    If I'm going to be riding my team really hard, how much charisma will I need to keep the team frightened so they stay motivated, yet don't want to leave?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Jason Fruge (@jasonfruge), CISO, Rent-a-Center.

    Thanks to our podcast sponsor, Expel

    Expel offers companies of all shapes and sizes the capabilities of a modern Security Operations Center without the cost and headache of managing one.

    In this episode

    • CISO's second job: applying lessons learned from the first one
    • Experts weigh in on what to do when a breach drops malware on you
    • How to motivate staff to push themselves beyond initial expectations?
    • What level of autonomy do you give your staff to make purchase decisions?
    34 min
  • How Would You Like Your Cloud Misconfigured?

    All links and images for this episode can be found on CISO Series

    Great, you just purchased the cloud. Are you a little confused as to what you're going to do with it? Not a problem. Let's get you set up right with a world class misconfiguration. That should leave you open to all kinds of breaches.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Johnathan Keith, CISO, Viacom/CBS Streaming.

    Thanks to our podcast sponsor, AppOmni

    AppOmni is building the future of SaaS security. We empower our users to enforce security standards across their SaaS applications, and enable them to remediate in confidence knowing they're fixing the most important SaaS security issues first. Contact us at www.appomni.com to find out who - and what - has access to your SaaS data.

    • Why do we hear so many stories about poor & misconfigured cloud services?
    • The benefits of Infrastructure as Code (IaC)
    • What makes a vendor meeting worth your time?
    • What's the best way to learn about a company's culture in a job interview?

    35 min
  • It's Only a Matter of Time Before We Lose Your Data

    All links and images for this episode can be found on CISO Series

    We're trying really hard to keep our customers' data safe, but we all know given the number of attacks happening, our number will eventually come up, and we'll lose your data just like every other organization you trusted.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Sandy Dunn (@sub0girl), CISO, Blue Cross of Idaho.

    Thanks to our podcast sponsor, Expel

    Expel offers companies of all shapes and sizes the capabilities of a modern Security Operations Center without the cost and headache of managing one.

    • Dissecting Allen Gwynn's "one strike" opinion piece
    • Transitioning cybersec into a mindset for all employees
    • Shifting the risk: buying cyberinsurance instead of tools
    • What's the proper way to behave during a breach?
    32 min
  • His Credentials Say "Yes" But His Behavior Says "No Way"

    All links and images for this episode can be found on CISO Series

    As good as our virtual bouncers are, they often let in people with what seems to be a valid ID, and then once they're in our nightclub they cause a disruption and we have to kick them out.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our sponsored guest is Sandy Wenzel (@malwaremama), cybersecurity transformation engineer, VMware.

    Sandy also recommends participating in Pro's vs. Joe's CTF.

    Thanks to our podcast sponsor, VMware

    In this episode:

    • How we have become more agile (and how we define agile)
    • Five skills every SOC analyst needs (and how to build them)
    • Lateral movement by threat actors (what have we heard enough of)
    • What are some good assignments to give a cybersecurity intern (and are there better ones?)

    37 min
  • We're Experts at Finding Everything You're Doing Wrong

    All links and images for this episode can be found on CISO Series

    We're a brand new consultancy and we promise if you just let us poke around your network, we'll find something wrong. Because everyone has something wrong in their network.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Phil Huggins (@oracuk), CISO, NHS Test & Trace, Department of Health and Social Care.

    Thanks to our podcast sponsor, VMware

    In this episode:

    • Prioritizing the security challenges around risk and compliance
    • What to consider before starting your own security consulting business
    • The most valuable things you should learn from peers in your network or community

    33 min
  • Hey Old Man, Go Rotate Your Own Passwords

    All links and images for this episode can be found on CISO Series

    If you're happy with your best practice of rotating passwords, that's great for you. Just don't lay your old-timey "rules for better security" on me boomer.

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Robb Reck (@robbreck), CISO on sabbatical and co-founder Colorado=Security, a podcast and Slack community.

    Thanks to our podcast sponsor, VMware

    In this episode:

    • Who is supposed to put "security" into the shifted left SDLC?
    • What's the scarcest resource to a CISO? Is it headcount or money?
    • What's the hardest part about being a CISO?
    • How to choose the "best" best practices.

    34 min
  • How CISOs Make It Worse for Other CISOs

    All links and images for this episode can be found on CISO Series

    https://cisoseries.com/how-cisos-make-it-worse-for-other-cisos/

    Are CISOs inappropriately putting pressure on themselves and is that hurting the rep of all CISOs as a result?

    This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Andy Ellis (@csoandy), operating partner, YL Ventures.

    Thanks to our podcast sponsor, Orca Security

    Orca Security provides instant-on security and compliance for AWS, Azure, and GCP - without the gaps in coverage, alert fatigue, and operational costs of agents or sidecars. Orca detects and prioritizes risk in minutes ﹣ not months ﹣ and is trusted by global innovators, including Databricks, Lemonade, Gannett, and Robinhood.

    In this episode:

    • Is the hiring process for CISOs broken?
    • Why CISOs aren't willing to share samples of their risk assessments
    • Working with a vCISO through an MSSP
    • What are the biggest misconceptions cybersecurity people have about CISOs?
    39 min
  • Excuse Me, What Bribes Do You Accept?

    All links and images for this episode can be found on CISO Series

    https://cisoseries.com/excuse-me-what-bribes-do-you-accept/

    The security vendor/practitioner sales cycle would go a lot faster and smoother if CISOs would just take an "incentive" for a meeting. Just tell me what "incentive" you would like. I'm sure it'll cost me a lot less than what I'm spending on marketing and sales.

    This episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Allison Miller (@selenakyle), CISO, reddit. Allison is available on reddit at /u/UndrgrndCartographer.

    Thanks to our podcast sponsor, Living Security

    Why We're Breaking Security Awareness (And You Should Too) Attend This Free, Virtual Conference From Your Home, Office, Or Even Your Couch. Living Security is breaking the mold of security awareness to wage war on the human risk factor with evolved strategies for the way we live, work, and play today. Join cybersecurity industry thought leaders for fresh, modern perspectives designed to help you change behaviors and reduce your organization's risk in a world where life happens online. This year's sessions will cover:

    • Human Risk Management
    • Social Engineering
    • DEI In Cybersecurity
    • Enterprise Security Awareness
    • Remote Working Security
    • Ransomware

    In this episode:

    • Relying on the end-user to make an app secure is, in essence, shipping insecure software
    • It's official: mandatory password changes are no longer in vogue
    • What incentives would you accept to take a meeting with a vendor
    32 min

About CISO Series Podcast

From the publisher's feed

Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.

More shows like CISO Series Podcast

Hacked by Hacked

Hacked

193 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

374 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,064 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

180 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners

CISO Tradecraft® by G Mark Hardy & Ross Young

CISO Tradecraft®

48 Listeners

Security You Should Know by CISO Series

Security You Should Know

9 Listeners