Secure & Simple — Podcast for Consultants and CISOs on Cybersecurity Governance and Compliance

Secure & Simple — Podcast for Consultants and CISOs on Cybersecurity Governance and Compliance

Download on the App Store

Secure & Simple — Podcast for Consultants and CISOs on Cybersecurity Governance and Compliance episodes

  • Penetration Testing & Threat Intelligence: Enhancing Cybersecurity | Interview with Sasa Jusic

    In this episode, host Dejan Kosutic interviews Sasa Jusic, a board member at Infigo IS and a cybersecurity expert. They delve deep into penetration testing and cyber threat intelligence, explaining their roles in enhancing cybersecurity. Learn about the differences between offensive and defensive security measures, the importance of DORA and ISO 27001 frameworks, the critical steps for preparing and executing successful penetration tests, and the elements of threat intelligence. Sasa also shares insights on the collaboration between IT and security teams, as well as the role of consultants in this evolving landscape.

    Links from the episode:
    - Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software
    - White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits
    - Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertise to potential clients: https://advisera.co/Consultant-Courses
    - Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account 
    - Beginner's Course for ISO, Cybersecurity, and AI Consultants: https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t
    - How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:https://advisera.co/GrowYourConsultancyTraining 

    • (00:00) - Interview with Sasa Jusic
  • (01:41) - Penetration Testing and Threat Intelligence Relationship
  • (06:23) - DORA and Its Impact on Cybersecurity
  • (08:22) - Types of Penetration Testing
  • (10:33) - Preparing for a Successful Penetration Test
  • (13:07) - Reporting and Translating Technical Findings
  • (15:56) - Acting on Penetration Test Reports
  • (19:52) - Understanding Threat Intelligence
  • (22:11) - Tools for Threat Intelligence
  • (29:01) - Common Misconceptions About Threat Intelligence
  • (31:58) - Opportunities for Cybersecurity Consultants
  • (36:42) - Key Recommendations for Security Officers
  • (40:13) - Resources for Consultants
  • 42 min
  • Simplifying ISO Standards: Insights and Best Practices | Interview with Jim Moran

    In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO of Advisera, welcomes Jim Moran, founder of SimplifyISO, to discuss the importance and methods of simplifying ISO management systems. Jim, with over 30 years of consulting experience, shares valuable insights on how overly complex management systems can hinder employee understanding and implementation, leading to higher costs and minimal return on investment. Key topics covered include the benefits of simplification, principles for effective ISO implementation, and the use of visuals and flowcharts. The episode also explores how consultants can leverage simplification to build stronger relationships with clients and scale their consulting businesses efficiently.
     
    Links from the episode:
    - Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software
    - White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits
    - Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertise to potential clients: https://advisera.co/Consultant-Courses
    - Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account 
    - Beginner's Course for ISO, Cybersecurity, and AI Consultants: https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t
    - How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:https://advisera.co/GrowYourConsultancyTraining 

    • (00:00) - Interview with Jim Moran
  • (01:20) - The Importance of Simplifying ISO Implementation
  • (03:34) - Key Concepts in ISO Simplification
  • (08:47) - Using Visuals and Flowcharts for ISO Processes
  • (11:49) - Simplifying Documentation and Internal Audits
  • (24:18) - Visual Aids and Risk Assessment in ISO
  • (31:42) - Microlearning for Cybersecurity Awareness
  • (36:26) - Automating Document Control in ISO Standards
  • (38:51) - Balancing Complexity and Simplicity in Software Tools
  • (47:26) - Simplification Strategies for Consultants
  • (56:40) - Resources for Consultants
  • 59 min
  • Mastering Internal Audits for ISO Standards | Interview with Carlos Cruz

    In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO at Advisera, welcomes Carlos Cruz, founder of Metanoia Consulting and a seasoned expert in ISO standards. Carlos and Dejan share best practices for performing internal audits across various ISO standards, including ISO 27001, and other cybersecurity frameworks such as NIS2 and DORA. Key topics discussed include the importance of internal audits, how to prepare effective audit checklists, and the role of AI in the future of auditing. The episode also explores the differences between internal audit programs and plans, the significance of audit objectives, and offers practical advice for consultants looking to expand their services into internal auditing. Carlos provides a deep dive into ensuring compliance and effectiveness while offering practical tips on maintaining independence and delivering valuable audit reports.

    Links from the episode:
    - Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software
    - White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits
    - Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertise to potential clients: https://advisera.co/Consultant-Courses
    - Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account 
    - Beginner's Course for ISO, Cybersecurity, and AI Consultants: https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t
    - How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:https://advisera.co/GrowYourConsultancyTraining 

    • (00:00) - Interview with Carlos Cruz on internal audits
  • (01:38) - Importance and Best Practices for Internal Audits
  • (04:55) - Audit Objectives and Their Importance
  • (09:38) - Creating an Internal Audit Program
  • (13:31) - Audit Plans and Internal Audit Checklists
  • (27:06) - Conducting the Main Audit
  • (30:10) - The Importance of Evidence in Auditing
  • (36:43) - Preparing the Audit Report
  • (42:13) - Consultants and Internal Audits
  • (49:29) - Remote Auditing: Challenges and Opportunities
  • (57:17) - AI in Internal Auditing
  • (01:04:34) - Resources for Consultants
  • 1 hr 6 min
  • Exploring Cyber Warfare: Risks, Strategies, and Solutions | Interview with Steve Winterfeld

    In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO of Advisera, welcomes Steve Winterfeld, a seasoned security consultant, fractional CISO, and author of the book 'Cyber Warfare Techniques, Tactics, and Tools for Security Practitioners.' The discussion revolves around the relevance of cyber warfare for companies, the different types of cyber threats, and strategic ways to address them. Steve shares insights on cyber warfare's impact on various sectors, from espionage and sabotage to operational tactics. He emphasizes the importance of risk assessment, the utility of frameworks like the MITRE ATT&CK framework, and approaches to security hygiene. The conversation provides a comprehensive look at how businesses can enhance their cybersecurity measures to safeguard against advanced threats.

    Links from the episode:
    - Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software
    - White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits
    - Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertise to potential clients: https://advisera.co/Consultant-Courses
    - Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account 
    - Beginner's Course for ISO, Cybersecurity, and AI Consultants: https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t
    - How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:https://advisera.co/GrowYourConsultancyTraining 

    • (00:00) - Interview with Steve Winterfeld
  • (01:10) - Understanding Cyber Warfare
  • (05:41) - Impact on Commercial Sector
  • (13:01) - Strategic, Operational, and Tactical Perspectives
  • (17:27) - Risk Management and Mitigation
  • (25:48) - Securing Supply Chains and Crisis Management
  • (30:36) - Validation Exercises and Technical Debt
  • (34:47) - Cybersecurity for Smaller Companies
  • (36:49) - Consulting Opportunities in Cybersecurity
  • (51:41) - Resources for Consultants
  • 54 min
  • Bridging the Cybersecurity Gap: From Tech Rooms to Boardrooms | Interview with Paul C Dwyer

    In this episode of the Secure and Simple Podcast, Dejan Kosutic, CEO of Advisera, interviews Paul C Dwyer, founder and CEO of Cyber Risk International and president of the ICTTF. They discuss digital resilience from a business and strategic standpoint, the role of company boards in cybersecurity, and how to effectively bridge the communication gap between technical experts and business leaders. Paul shares insights from his extensive 30-year career across military, law enforcement, and business sectors, emphasizing the importance of aligning cybersecurity and business strategies, understanding the core business, and enhancing communication skills among cybersecurity professionals to engage effectively with board members.

    Links from the episode:
    - Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software
    - White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits
    - Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertise to potential clients: https://advisera.co/Consultant-Courses
    - Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account 
    - Beginner's Course for ISO, Cybersecurity, and AI Consultants: https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t
    - How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:https://advisera.co/GrowYourConsultancyTraining 

    • (00:00) - Interview Paul C Dwyer
  • (01:55) - Communication Gaps in Cybersecurity
  • (03:00) - Importance of Leadership in Cybersecurity
  • (07:17) - Building Trust and Rapport
  • (09:47) - Soft Skills and People Skills
  • (18:09) - Connecting Cybersecurity with Business Strategy
  • (23:58) - Understanding Resilience and Cybersecurity
  • (28:07) - Disaster Recovery and Business Continuity
  • (33:05) - Integrating Cyber Risk into Enterprise Risk Management
  • (39:21) - Supply Chain Security and Resilience
  • (44:58) - Effective Communication with the Board
  • (49:38) - Resources for Consultants
  • 51 min
  • Mastering Integrated ISO Management Systems | Interview with Jim Moran

    In this episode of Secure and Simple Podcast, hosted by Dejan Kosutic, we are joined by Jim Moran, founder of Simplify ISO and member of the ISO Committee 280. With over 30 years of experience in consulting and various ISO standards, Jim shares his insights on the High-level Structure (HLS) of ISO management standards and the integration of various ISO standards into a cohesive management system. This episode covers strategies for merging ISO 9001, ISO 27001, and other standards, the benefits of HLS for integrated management systems, the importance of executive involvement, and recent updates to ISO 9001. Ideal for consultants, CISOs, and cybersecurity professionals, this episode provides practical tips and expertise on effectively implementing integrated management systems.

    Links from the episode:
    - Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software
    - White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits
    - Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertise to potential clients: https://advisera.co/Consultant-Courses
    - Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account 
    - Beginner's Course for ISO, Cybersecurity, and AI Consultants: https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t
    - How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:https://advisera.co/GrowYourConsultancyTraining 

    • (00:00) - Interview with Jim Moran
  • (01:49) - Understanding High-Level Structure (HLS)
  • (11:30) - The Role of Annexes in ISO Standards
  • (15:22) - Integrated Management Systems in Practice
  • (22:38) - Documenting Integrated Management Systems
  • (27:07) - Integrating Management Reviews
  • (35:42) - Starting with One Standard vs. Multiple Standards
  • (39:12) - Changes in ISO 9001 and Other Standards
  • (43:17) - Future Trends: AI and Cybersecurity
  • 49 min
  • Volunteer Work in Cybersecurity Nonprofits | Interview with Aruneesh Salhotra

    Join Dejan Kosutic, CEO of Advisera, on the Secure and Simple Podcast as he delves into the importance of cybersecurity NGOs with expert guest Aruneesh Salhotra. Explore the impact of organizations like OWASP and the Eclipse Foundation on global cybersecurity standards, the benefits of volunteering in these NGOs, and the influence of these nonprofits on government policies. Learn about Aruneesh’s involvement with projects like OWASP AI Exchange and AI BOM, and gain insights on how consultants and CISOs can leverage these organizations for professional growth and thought leadership.

    Links from the episode:
    - Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software
    - White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits
    - Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertise to potential clients: https://advisera.co/Consultant-Courses
    - Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account 
    - Beginner's Course for ISO, Cybersecurity, and AI Consultants: https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t
    - How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:https://advisera.co/GrowYourConsultancyTraining 

    • (00:00) - Interview with Aruneesh Salhotra
  • (02:42) - Differences Between Cybersecurity NGOs
  • (04:55) - Governance-Oriented Cybersecurity NGOs
  • (06:19) - Educational Initiatives in Cybersecurity
  • (06:54) - OWASP AI Exchange and Its Impact
  • (13:51) - Volunteering in Cybersecurity NGOs
  • (25:45) - Aruneesh's Involvement in OWASP Projects
  • (34:43) - Resources for Consultants
  • 37 min
  • Building a Business-Aligned Cybersecurity Strategy | Interview with Thom Langford

    In this episode, Dejan Kosutic, CEO at Advisera, chats with Thom Langford, CTO of the EMEA region at Rapid7 and a director at (TL)2 Security. Thom shares invaluable insights from his 30-year career in cybersecurity, focusing on creating a business-aligned cybersecurity strategy and building a cybersecurity culture. Learn why understanding your business is crucial for effective cybersecurity, how to integrate security without hindering business operations, and ways to leverage cybersecurity as a competitive advantage. Thom also discusses the importance of risk management and how to effectively communicate cybersecurity needs to senior leadership.

    Links from the episode:
    - Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software
    - White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits
    - Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertise to potential clients: https://advisera.co/Consultant-Courses
    - Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account 
    - Beginner's Course for ISO, Cybersecurity, and AI Consultants: https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t
    - How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:https://advisera.co/GrowYourConsultancyTraining 

    • (00:00) - Interview with Thom Langford
  • (01:18) - Understanding Cybersecurity Strategy
  • (04:00) - Implementing Effective Cybersecurity Measures
  • (08:56) - Risk Management in Cybersecurity
  • (17:02) - Cybersecurity as a Competitive Advantage
  • (28:31) - Security Professionals' Role in Business
  • (30:13) - People-Centered Security
  • (33:58) - Effective Training Strategies
  • (37:49) - Creating a Security Culture
  • (42:01) - The Power of Storytelling and Humor
  • (51:53) - Resources for Consultants
  • 54 min
  • Demystifying Corporate Governance With ISO 37000 | Interview with George Kesteven

    In this episode of the Secure and Simple podcast, host Dejan Kosutic interviews George Kesteven, CEO of Frontex, who shares his experience in corporate governance. They discuss the critical importance of proper documentation and knowledge management in organizations for effective governance and compliance. The conversation covers the fundamentals of ISO 37000, how it helps organizations meet their governance objectives, and the distinctions between governance and management. They also explore how consultants can leverage ISO 37000 to assist organizations in achieving well-defined and structured governance systems.

    Links from the episode:
    - Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software
    - White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits
    - Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertise to potential clients: https://advisera.co/Consultant-Courses
    - Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account 
    - Beginner's Course for ISO, Cybersecurity, and AI Consultants: https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t
    - How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:https://advisera.co/GrowYourConsultancyTraining 

    • (00:00) - Interview with George Kesteven
  • (01:14) - The Importance of Governance and Compliance
  • (04:05) - Corporate Governance Management Systems Explained
  • (07:18) - ISO 37000: Principles and Applications
  • (14:26) - Governance vs. Management
  • (18:21) - Consultants' Role in Governance
  • (22:41) - The Value of Proper Documentation
  • (32:00) - ISO 37000: Starting Points for Consultants
  • (36:18) - Measuring Governance with ISO 37004
  • (38:44) - ESG and Corporate Governance
  • (42:13) - Resources for Consultants
  • 44 min
  • U.S. vs International and European Cybersecurity Standards | Interview with John Verry

    In this episode, host Dejan Kosutic, CEO of Advisera, welcomes John Verry, Managing Director at CBIZ Pivot Point Security consulting company. With over 25 years of experience and managing more than a thousand clients, John shares his immense expertise in various cybersecurity frameworks, including ISO 27001, CMMC, HIPAA, and HITRUST. The discussion delves deep into the complexities and opportunities within cybersecurity governance, the nuances of different frameworks (especially ISO 27001 and HITRUST), and the impact of AI and privacy regulations. Whether you're a consultant, CISO, or cybersecurity professional, this episode has valuable insights to help you navigate the ever-evolving landscape of cybersecurity compliance.

    Links from the episode:
    - Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software
    - White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits
    - Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertise to potential clients: https://advisera.co/Consultant-Courses
    - Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account 
    - Beginner's Course for ISO, Cybersecurity, and AI Consultants: https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t
    - How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:https://advisera.co/GrowYourConsultancyTraining 

    • (00:00) - Interview with John Verry
  • (00:15) - Meet the Guest: John Verry
  • (01:10) - Comparing Cybersecurity Frameworks
  • (05:12) - The Impact of AI and Other Frameworks
  • (07:46) - HITRUST and Its Market
  • (12:00) - HIPAA vs. HITRUST
  • (14:45) - ISO 27001 vs. SOC 2 in the US Market
  • (17:27) - Working with European Clients
  • (24:35) - Navigating Privacy Laws in the US and Europe
  • (29:20) - The Role of AI in Consulting
  • (40:13) - Resources for Consultants
  • 42 min

About Secure & Simple — Podcast for Consultants and CISOs on Cybersecurity Governance and Compliance

From the publisher's feed

“Secure & Simple” demystifies governance and compliance challenges faced by CISOs, consultants, and other cybersecurity professionals. The podcast is hosted by Dejan Kosutic, an expert in cybersecurity governance, ISO 27001, NIS2, and DORA. The episodes present topics in an easy-to-understand way and provide you with insight you won’t be able to find elsewhere.