
Sign up to save your podcasts
Or


This episode features an interview with Greg Crowley, CISO at eSentire. eSentire is the authority in managed detection and response services. They protect critical information for over two-thousand organizations across more than 80 countries from cyberthreats. Prior to joining eSentire, Greg served as VP of Cybersecurity and Network Infrastructure at WWE, where he spent over 17 years. On this episode, host Tim Chase and Greg discuss preventing alert fatigue within your organization, addressing the talent shortage in cybersecurity, and the benefits and challenges posed in the security industry by artificial intelligence.
Key Quotes
”It's always been the cat and mouse game in security. You have a neural network that is out there creating new content, and then you have the opposing network that is looking to detect the artificially created content. And so same thing as the good guys and the bad guys, or the threat actors and the defenders, the red team and the blue team. But in this case, it's actually making the AI stronger because the more we’re able to detect what's fake, then the AI learns and the AI will generate better fakes.”
*”Fishing has been a problem for a long time. [But] I think what AI is doing is lowering the bar of entry. So, whereas maybe the threat actors used to have to have a certain amount of technical capability, it's just going to become a lot easier for them to execute upon the nefarious activity.”
*”If there's constantly a false alert, false alert, false alert, and 99 percent of them are, then it is very likely that the true positives are gonna slip through because you see so few of them. So you're just getting lost in the noise. It's the needle in the haystack that's gonna get through, and that's the one that's gonna come back and bite you.”
*”What I look for is passion. If you're curious, if you like solving puzzles, if you like pulling out threads and doing some type of investigation, those are the qualities that I would look for. If you have that curiosity and passion, then you can learn the technical bits and bites after.”
*“I have this passion for protecting the good guys, protecting the little guy. I want to teach the little guy how to protect themselves. It's part of my DNA. I’ve always seen myself as a defender, as protecting the little guy as being on the side of good.”
Time Stamps
[1:19] What does the advent of Chat GPT and generative AI mean for the cybersecurity industry?
[4:35] What are the security downfalls of AI?
[8:44] What are best practices for addressing alerts and preventing alert fatigue?
[13:46] Addressing the talent void in cybersecurity
[17:24] What advice would Greg give someone just entering the cybersecurity field?
[24:33] How did Greg first get involved in cybersecurity? And what was his path to CISO?
Links
Connect with Greg on LinkedIn
Learn more about eSentire
This podcast is brought to you by Lacework, the leading data-driven cloud-native application protection platform. Lacework is trusted by nearly 1,000 global innovators to secure the cloud from build to run. Lacework delivers true end-to-end protection, empowering customers to prioritize risks, find known and unknown threats faster, achieve continuous cloud compliance, and work smarter–not harder–all from one unified platform. Learn more at Lacework.com.
This episode features an interview with author and 7-time CIO Mark Settle. Mark has served as CIO at companies like Okta, Visa and Arrow Electronics. And he has published two books: Truth from the Trenches: A Practical Guide to the Art of IT Management and Truth from the Valley: A Practical Primer on Future IT Management Trends. On this episode, host Tim Chase and Mark talk about the competencies you need to have if you want to be in an IT leadership role, how to communicate effectively with the board and the rest of the C-suite, and the lessons he’s learned as a 7-time CIO.
Key Quotes
*”If you really want to have an impact over time, and really start realizing your market equity, not your brand equity, but what you bring to that next job over time will be less and less about what you know about blockchain or large language models and more and more and more if you understand how do we really make money here? And like, where are the high leverage points for us to succeed?”
*If you're managing an IT team on a strategic basis and not just lurching from one budget to another or tactical crisis to another, you really want to think into the future two or three years. And I tell people it's instructive. Take a blank sheet of paper, a whiteboard or whatever, and sketch out the organization you think your company needs in two years from now or three years from now, and what skills you're going to need. Because otherwise, the tech debt that you have manifests itself in the skills of your team.”
*”I think AI is a perfect example of this. If you've gone through the last three or four budget cycles as a CIO and you've said to yourself, ‘Well, we really don't need any machine learning modeling capabilities within the company today, I can kick that can down the road another three or four budget cycles,’ then your CEO comes in and says, ‘What are we doing about generative AI?’”
Time Stamps
[1:08] What does it take to be an IT leader?
[2:53] What is the future of IT management?
[8:06] How to convey IT priorities to your CFO
[9:37] What are emerging security concerns?
[11:16] How is security a business enabler?
[13:32] How companies could benefit from adopting consumer-grade end user authentication procedures
[18:02] Why delegation is important as a CIO
Links
Connect with Mark on LinkedIn
Read Truth from the Trenches: A Practical Guide to the Art of IT Management
Read Truth from the Valley: A Practical Primer on Future IT Management Trends
This podcast is brought to you by Lacework, the leading data-driven cloud-native application protection platform. Lacework is trusted by nearly 1,000 global innovators to secure the cloud from build to run. Lacework delivers true end-to-end protection, empowering customers to prioritize risks, find known and unknown threats faster, achieve continuous cloud compliance, and work smarter–not harder–all from one unified platform. Learn more at Lacework.com.
This episode features an interview between host Andy Schneider and Julie Chickillo, VP and Head of Cybersecurity at Guild, a learning marketplace offering classes, programs, and accredited college degrees for working adults. Julie has over 20 years of experience in Information Security Governance, Risk and Compliance, Threat & Vulnerability, IT Audit, Privacy, DevSecOps and Legal. Julie has been recognized with the APEX CISO of the Year Award in Colorado and is one of the inspiring leaders of the Lacework Secured by Women Initiative.
Key Quotes
*”Once you can get into the contracts, that's going to help you understand the business. The stuff in the contracts is what's important and you'll start seeing what they'll fight for in the contract. That's one of the ways that I get immediate kudos or brownie points, when I start supporting sales.”
*”I [start by doing] a listening tour - stop and listen. I make a point to go to all the business meetings that I can get myself into. I go to all the strategy meetings and just listen for a while to understand where are the important pieces of the business? And really going back to those teams and finding out how you can support them before you even ask them to change anything. I think that's one of the big misses that we see in security.”
*”If you're not supporting the business, you're out of the business. And so I think [it’s important to have] that mindset and understanding that it's not just about you. There's a bigger business that you really have to pay attention to.”
*”Not every company's going to have a data ops team, but we are starting to see [data] becoming really important to most companies. If your data's moving very, very quickly, it's sort of like at the beginning of the DevOps practice where you were starting to see how can we ship small things? How can we move very quickly? And how can we make small changes with big impacts without having to wait six months for it to happen? This is happening in the data ops industry. There is a really big move for data to support the business.”
*”We're starting to see some really great technology coming out and just a practice around not only where the data lives, but how you're securing it where it lives, how you secure it when it moves, and then understanding the privacy impacts.”
Time Stamps
[1:11] What does Guild do?
[2:03] How does Julie’s team act as a business enabler?
[4:30] Tell me about the merging of data ops and security
[6:47] Is data scaling like security?
[8:01] Is it worth having a data ops person on your cybersecurity team?
[10:18] When do you know that your data is secure?
[1:15] How is privacy keeping up with this shift to a data focus in cybersecurity?
[14:12] What makes a good leader?
[16:01] Guild is a woman-led organization. What advice would Julie give to women leaders in security?
[21:11] What has been the biggest learning in Julie’s career?
[23:28] How did Julie get involved in security?
[27:50] How does Julie’s background in legal intersect with her current work in DevSecOps?
Links
Connect with Julie on LinkedIn
Learn more about Guild
This episode features an interview with Rohit Parchuri, SVP and CISO at Yext, masters of online brand management trusted by thousands of companies around the globe, including Verizon, Campbell’s, and Cox. Rohit is a trusted information security executive who currently heads a global security program at Yext. He is responsible for building and executing their cyber security governance and also educates both the board of directors and executive management on cyber security affairs. And in this episode, host Andy Schneider and Rohit discuss how to convey cybersecurity maturity and risk to the board, collaborating as a key to success, and building a robust, comprehensive cybersecurity program.
Key Quotes
*“Trust is everything. What I say is business first, trust second, and cyber third. That's the mantra I go with. Without business, nothing exists, of course. But trust is literally the next element that you have to focus on.”
*”When you go into the board discussion, all you're talking about is your top five risks. Don't just paint it as a cybersecurity risk. Paint it as an organizational risk. Because that’s how board members and the executives connect to it, if there’s a significant risk to revenue or reputation.”
*“Collaboration is such a key for any business leader. Without that, you're acting in a silo. And if you're acting in a silo, you're not benefiting the company.”
Time Stamps
[0:54] What are Rohit’s top cybersecurity priorities?
[2:39] How does he address risk?
[5:33] How does he convey cybersecurity concerns to the board?
[12:13] Is there a misalignment between talent supply and demand?
[15:28] How do you build trust as a cybersecurity professional?
[18:27] What makes a good cybersecurity leader?
[21:00] What was Rohit’s path to becoming a CISO?
[25:19] What is the scope of Rohit’s role as CISO at Yext?
[27:56] Rohit shares a story of a lesson he learned as a young cybersecurity professional
[29:55] What’s one piece of advice Rohit would give someone starting a career in cybersecurity?
Links
Connect with Rohit on LinkedIn
Check out Yext
This episode features an interview with Gerald Beuchelt, the CISO at Sprinklr, the leader in customer experience management, serving companies like Microsoft, P&G, and 50% of the Fortune 100. Gerald has nearly 30 years of experience in IT, having served in leadership roles at companies like MITRE, Demandware, a Salesforce company, and LogMeIn. He is also a cyber security consultant and advisor. And in this episode, host Andy Schneider and Gerald discuss fostering an organization-wide culture of security through effective employee education, communication with leaders, and building trust as a security leader.
Key Quotes
*”Standing in the limelight and being exposed is very humbling on the one side. But on the other side, it's like once you go through it, it does give you more confidence about yourself. And I think that's something that is important as you're facing an environment that is sometimes skeptical of what security people are saying and for all the right reasons.”
*”We think of people, processes, and technology. Strong gates have big locks on those gates. If nobody’s protecting that kind of wall and knows what to do if an adversary’s coming in, just use a ladder and climb over it, and it’s a done deal, right? It’s exactly the same thing when it comes to security. It’s mainly about people and processes first. And then we can see how we can use technology as a force multiplier, as something that enables certain things that we couldn’t do otherwise. ”
*”Once you can relate security issues in a very concrete and tangible way, education sticks much better. And that is how you build education over time.”
*”The vast majority of senior leaders, executive leaders, board members do fully understand the importance of security. They sometimes just don't know what they can do in order to help. So really helping them to help you in terms of structuring education, in terms of structuring outreach to employees, customers, contractors, I think that is really important. And once that clicks, it becomes self-reinforcing, because at the end of the day, the customers are happier. That goes back to the sales reps, that goes back to tangibly increase the revenue, but even customer satisfaction scores can go up. And all those things reinforce a positive security culture just the same way a negative security culture can take this thing down.”
“If I'm going into an executive leadership team discussion or board meeting, I'm starting to say, ‘Well, let me talk about the structure of the TCP/IP package that we discovered in the last meeting.’ You lost them. They understand that this is important and they may even be awed by your knowledge and make you feel good for a short period of time. But in the long run, this is not really sustainable, right? It doesn't really convey the kind of information that senior leaders would need in order to be able to help you. You need to translate this into things that are tangible. Cost, benefits, risk that you can mitigate.“
Time Stamps
[0:33] Introducing Gerald Beuchelt, the CISO at Sprinklr
[1:18] What is the scope of Gerald’s role at Sprinklr?
[3:19] What is the CISO role like at a company that is purely on the cloud? What are Gerald’s top priorities and concerns?
[6:19] How does Gerald educate employees on security?
[10:15] How do you make security relevant from a business perspective?
[12:25] How do you build trust as a new CISO?
[14:55] What was Gerald’s path to becoming the CISO at Sprinklr?
[18:33] Does having experience in sales lend itself to being a CISO?
[22:27] Gerald shares a story of what happens when you apply old controls to new environments
Links
Connect with Gerald on LinkedIn
Check out Sprinklr
The cloud moves fast. And the threat landscape, even faster.
Protecting your cloud-native applications from code to production is imperative. And building the strong foundations of security into everything you create is a must. If your cloud-native business prioritizes security while innovating, this is the podcast for you.
On Code to Cloud, we’ll hear from Chief Information Security Officers and security thought leaders about the strategies they use to succeed in an ever-changing environment. Learn how they’ve approached industry trends and challenges, how they’re “shifting left”, and what opportunities lie ahead.
We are on a journey to securing what’s next. Join us for Code to Cloud. Hosted by Lacework’s Field CISO for EMEA, Andy Schneider, and Field CISO for North America, Tim Chase. Powered by the team at Lacework.
From the publisher's feed