
Sign up to save your podcasts
Or


Send us Fan Mail
Ever wonder how to protect sensitive data when you don't have an IT department? In this revealing conversation, two pharmaceutical industry veterans who recently launched their own consulting businesses share the cybersecurity challenges they never anticipated after leaving corporate America.
Katie Hewitt, founder of BioVenture Advisors, and Laura Viaches, president of Endeavor Pharma Solutions, spent over 20 years each at Eli Lilly before venturing out on their own. Their transition from having robust corporate security infrastructure to becoming their own CISOs overnight offers powerful lessons for entrepreneurs handling confidential information. From Katie's experience juggling client demands before even setting up a domain name to Laura's methodical "stealth mode" approach to building secure systems, their contrasting journeys highlight different paths to the same goal: protecting client trust.
The conversation reveals startling gaps in the healthcare consulting ecosystem, where clients with valuable intellectual property rarely audit the security practices of their advisors. "I'm more surprised that's not a question they're asking," notes Katie, highlighting how even sophisticated biotech companies often overlook security verification until regulatory requirements or funding rounds force the issue.
Cybersecurity experts Aaron, Todd, and Cody offer practical advice for entrepreneurs navigating these challenges without enterprise budgets. Their recommendations focus on process-first approaches – identifying critical assets, working in client environments whenever possible, and implementing basic controls like multi-factor authentication before investing in complex solutions. The group explores how AI tools create new security considerations, particularly around meeting documentation and data retention.
Whether you're launching a new venture or helping clients through their growth journey, this discussion delivers actionable insights about balancing security with entrepreneurial agility. The most valuable takeaway? "If you're a small business entrepreneur, you are the CIO and you are the CISO," Katie reminds us – taking this responsibility seriously from day one can transform security from a burden into a competitive advantage.
🔗 Connect with Us & Get in Touch
Tune in to Simplifying Cyber wherever you get your podcasts, or watch exclusive video content right here on the channel. Subscribe for hot takes on emerging technologies, tips and tricks for everyone looking to stay secure, and in-depth conversations about complex cybersecurity topics.
No gatekeeping and no BS. We’re here to simplify.
Official Website: www.revealrisk.com
LinkedIn: https://www.linkedin.com/company/reveal-risk
🤘 Stay Secure with Us
If this content helped you understand cybersecurity better, please give it a thumbs up, subscribe to our channel for more expert insights, and hit the notification bell so you don't miss our latest updates.
Reveal Risk delivers cybersecurity results, not just reports.
Send us Fan Mail
Artificial intelligence has firmly established itself at the forefront of the cybersecurity agenda, creating both unprecedented opportunities and complex challenges for security leaders. In this eye-opening conversation with cybersecurity veteran Tim Sewell, we dive deep into the realities of implementing effective AI governance and security practices in today's rapidly evolving threat landscape.
Tim shares invaluable insights on how AI has fundamentally transformed the cybersecurity domain, comparing this shift to the rise of desktop computing or cloud adoption. He cautions against the "wild west" approach to AI governance that many organizations have inadvertently embraced, where tools are deployed without proper oversight or awareness. Most concerning is his observation that AI is increasingly being integrated into existing business processes by vendors or partners without explicit notification, creating dangerous blind spots in security programs.
The discussion reveals surprising developments in third-party risk management, where AI tools now handle everything from vendor questionnaires to SOC 2 report analysis. We explore the troubling reality of "AI sending questionnaires to AI that is responding to questionnaires," raising critical questions about trust and verification in our increasingly automated security ecosystem. Tim provides practical guidance for security teams on transparency in AI usage, particularly when making decisions that may later require justification in legal proceedings.
Despite the focus on advanced AI capabilities, Tim emphasizes the continued importance of security fundamentals. He notes that sophisticated nation-state actors are increasingly targeting basic vulnerabilities like buffer overflows and cross-site scripting, especially in critical infrastructure with legacy technologies. For new security leaders, his advice is refreshingly straightforward: identify what you're protecting, assess existing controls, and practice your incident response.
Listen now for essential insights on navigating the AI security landscape, from governance frameworks to practical implementation strategies that balance innovation with risk management. Whether you're a CISO looking to update your program or a security professional wanting to stay ahead of emerging threats, this episode delivers actionable knowledge for securing your organization in the age of artificial intelligence.
🔗 Connect with Us & Get in Touch
Tune in to Simplifying Cyber wherever you get your podcasts, or watch exclusive video content right here on the channel. Subscribe for hot takes on emerging technologies, tips and tricks for everyone looking to stay secure, and in-depth conversations about complex cybersecurity topics.
No gatekeeping and no BS. We’re here to simplify.
Official Website: www.revealrisk.com
LinkedIn: https://www.linkedin.com/company/reveal-risk
🤘 Stay Secure with Us
If this content helped you understand cybersecurity better, please give it a thumbs up, subscribe to our channel for more expert insights, and hit the notification bell so you don't miss our latest updates.
Reveal Risk delivers cybersecurity results, not just reports.
Send us Fan Mail
What can the largest diamond heist in history teach us about modern cybersecurity? When $100 million in diamonds vanished from Belgium's supposedly impenetrable Diamond Center vault, it wasn't cutting-edge technology that failed—it was people and processes.
Join host Aaron Pritz and senior cybersecurity consultant Rebecca as they unpack the fascinating story of the 2003 Antwerp Diamond Heist in this surprise mystery episode. Piece by piece, they reveal how jewel thieves bypassed sophisticated security measures using remarkably simple techniques: hairspray on heat sensors, electrical tape over light detectors, and basic tools to pry open safety deposit boxes. More importantly, they uncover how fundamental breakdowns in process and human vigilance created the perfect conditions for this historic theft.
The parallels to modern cybersecurity are striking and sobering. Just as the Diamond Center's management skipped background checks and ignored maintenance warnings to save money, many organizations today prioritize convenience over security or postpone critical patches to avoid disruption. The heist demonstrates how social engineering, insider threats, and complacency can defeat even the most impressive security technologies—a lesson that remains painfully relevant in our digital world.
Whether you're responsible for protecting digital assets or physical ones, this episode offers valuable insights into the delicate balance between technology, people, and process in creating truly effective security. Listen now to discover how the most catastrophic security failures often stem not from sophisticated attacks, but from neglecting the basics.
References:
1. https://www.osti.gov/servlets/purl/1115483
2. https://www.wired.com/2009/03/ff-diamonds-2/
3. https://www.bbc.co.uk/programmes/w3cszdjz
🔗 Connect with Us & Get in Touch
Tune in to Simplifying Cyber wherever you get your podcasts, or watch exclusive video content right here on the channel. Subscribe for hot takes on emerging technologies, tips and tricks for everyone looking to stay secure, and in-depth conversations about complex cybersecurity topics.
No gatekeeping and no BS. We’re here to simplify.
Official Website: www.revealrisk.com
LinkedIn: https://www.linkedin.com/company/reveal-risk
🤘 Stay Secure with Us
If this content helped you understand cybersecurity better, please give it a thumbs up, subscribe to our channel for more expert insights, and hit the notification bell so you don't miss our latest updates.
Reveal Risk delivers cybersecurity results, not just reports.
Send us Fan Mail
Grace Chi, co-founder and COO of PulseDive, takes us deep into the often overlooked world of cyber threat intelligence networking. Grace has become a passionate advocate for the human connections that power effective security programs, conducting groundbreaking research on how threat intelligence practitioners share information.
What makes this conversation especially valuable is Grace's focus on the practical realities of threat intelligence implementation. She reveals that while formal structure or groups like ISACs provide important frameworks, the most timely and actionable intelligence typically flows through one-to-one relationships and trusted peer networks. These connections become critical during security incidents, when having someone who can provide just-in-time context about a threat can make all the difference between detection and compromise.
The discussion tackles common pitfalls in threat intelligence program development, particularly the tendency to invest in platforms without proper implementation planning or ongoing maintenance resources. Grace offers concrete advice for organizations at different maturity levels, emphasizing the importance of starting with clear requirements, assigning dedicated point persons for implementation, and understanding pricing models before making significant investments.
For those building threat intelligence capabilities from scratch, this episode provides a roadmap that focuses on identifying organizational pain points, leveraging existing talent, and implementing capabilities incrementally rather than attempting to configure every available feed immediately. Grace also highlights the critical distinction between external intelligence sources and the often-underutilized wealth of internal telemetry and observations.
Beyond the tactical aspects, we explore how threat intelligence must be communicated differently to technical teams versus executive stakeholders, and how building a diverse network across multiple channels creates compounding value over time. Whether you're a seasoned security professional or just beginning to explore threat intelligence, this conversation offers insights that will help you build more effective security capabilities through the power of community.
🔗 Connect with Us & Get in Touch
Tune in to Simplifying Cyber wherever you get your podcasts, or watch exclusive video content right here on the channel. Subscribe for hot takes on emerging technologies, tips and tricks for everyone looking to stay secure, and in-depth conversations about complex cybersecurity topics.
No gatekeeping and no BS. We’re here to simplify.
Official Website: www.revealrisk.com
LinkedIn: https://www.linkedin.com/company/reveal-risk
🤘 Stay Secure with Us
If this content helped you understand cybersecurity better, please give it a thumbs up, subscribe to our channel for more expert insights, and hit the notification bell so you don't miss our latest updates.
Reveal Risk delivers cybersecurity results, not just reports.
Send us Fan Mail
How prepared is your organization for disruption?
In our latest episode, we dive deep into the critical topic of Business Continuity Planning (BCP) with cybersecurity expert and new Reveal Risk Director Todd Wilkinson.
As digital dependencies grow, the way companies approach BCP must evolve. Todd highlights the shift in ownership from IT departments to business leaders, shedding light on the necessity for everyone in the organization to take accountability for continuity strategies.
Drawing from his wealth of experience, Todd recounts compelling stories of real-world failures and the stark realities of service disruptions, particularly in the healthcare sector. He explains how reliance on SaaS and cloud services has transformed the landscape of planning, creating both opportunities and vulnerabilities.
Listeners will gain valuable insights into best practices for establishing effective BCP protocols, including the vital distinction between BCP and disaster recovery planning. We tackle the importance of clear communication strategies during crises, the need for frequent testing, and the changing roles of different departments when it comes to continuity planning.
Engaging and informative, this episode encourages organizations to rethink BCP as a crucial aspect of operational resilience rather than just a checklist for IT departments.
Subscribe, share, and let us know how your organization is preparing for unexpected challenges or if you need help along the way!
🔗 Connect with Us & Get in Touch
Tune in to Simplifying Cyber wherever you get your podcasts, or watch exclusive video content right here on the channel. Subscribe for hot takes on emerging technologies, tips and tricks for everyone looking to stay secure, and in-depth conversations about complex cybersecurity topics.
No gatekeeping and no BS. We’re here to simplify.
Official Website: www.revealrisk.com
LinkedIn: https://www.linkedin.com/company/reveal-risk
🤘 Stay Secure with Us
If this content helped you understand cybersecurity better, please give it a thumbs up, subscribe to our channel for more expert insights, and hit the notification bell so you don't miss our latest updates.
Reveal Risk delivers cybersecurity results, not just reports.
Send us Fan Mail
Unlock the secrets of a successful career in cybersecurity with our guest, David Gee, a recently retired industry veteran and author of "The Aspiring CIO and CISO."
Amazon: https://a.co/d/9FCsBQR
Packt (includes a promotion for the e-book version!): https://www.packtpub.com/en-us/product/the-aspiring-cio-and-ciso-9781835469194?srsltid=AfmBOooJFrNzjkRT_cLx3ux-ErfFownjl1EMB-dTupfrpBtI7QMw8103
David takes us on a captivating journey through his diverse career, sharing transformative experiences from working across the US, China, Japan, and Australia. Discover how he navigated the complexities of being a CIO and CISO in different industries, and learn from his unique insights into continuous learning and adaptability. David also unveils the SKB (Skills, Knowledge, Behavior) assessment tool he used to foster talent development and promote diversity at Eli Lilly Japan.
In our engaging conversation, we discuss the evolving role of a modern CISO, where the balance between technical know-how and soft skills is crucial. David, Cody, and Aaron dive into common misconceptions about the CISO role, particularly the narrow focus on technical skills alone. Through anecdotes about bot attacks and the Colonial Pipeline incident, we highlight the critical need for strategic thinking, stakeholder management, and effective communication. These stories underscore the importance of having a well-rounded skill set to thrive in the cybersecurity realm.
As we wrap up, we reflect on the art of making career decisions that resonate with one's passion and promote long-term growth. The implementation of SecureCard Warrior at HSBC serves as a case study for setting clear objectives and achieving data-driven outcomes. David generously shares personal insights about aligning career choices with personal values and finding true fulfillment. Join us in this enlightening episode, where we celebrate David's global perspectives and express our deep appreciation for his valuable contributions to the cybersecurity community.
🔗 Connect with Us & Get in Touch
Tune in to Simplifying Cyber wherever you get your podcasts, or watch exclusive video content right here on the channel. Subscribe for hot takes on emerging technologies, tips and tricks for everyone looking to stay secure, and in-depth conversations about complex cybersecurity topics.
No gatekeeping and no BS. We’re here to simplify.
Official Website: www.revealrisk.com
LinkedIn: https://www.linkedin.com/company/reveal-risk
🤘 Stay Secure with Us
If this content helped you understand cybersecurity better, please give it a thumbs up, subscribe to our channel for more expert insights, and hit the notification bell so you don't miss our latest updates.
Reveal Risk delivers cybersecurity results, not just reports.
Send us Fan Mail
Unlock the secrets of effective insider risk management with Marene Allison, the former CISO of Johnson & Johnson, as she takes us on a journey through her illustrious career in cybersecurity. From her intriguing transition from military police to managing IT security for the World Cup, Marene shares captivating stories like thwarting a logic bomb attempt at Medco. Her emphasis on prioritizing process over technology offers invaluable insights into tackling insider threats, legacy technology challenges, and strategic loss prevention. Marene's thoughtful approach to cybersecurity underscores the impact of collaboration, highlighting the necessity of engaging with non-IT departments to safeguard critical data assets.
In a conversation rich with wisdom and experience, we also explore the transformative power of mentorship with Cody, an advocate for the "pay it forward" philosophy. By fostering a culture of reciprocity, Cody inspires his mentees to guide others, amplifying the positive effects of mentorship in the cybersecurity field. This episode celebrates the unique skills that military veterans bring to the corporate world, emphasizing their significant contributions to data protection and security strategies. Join us for a thought-provoking dialogue that not only educates but also inspires a new generation of cybersecurity professionals to build a more secure future through collaboration and mentorship.
🔗 Connect with Us & Get in Touch
Tune in to Simplifying Cyber wherever you get your podcasts, or watch exclusive video content right here on the channel. Subscribe for hot takes on emerging technologies, tips and tricks for everyone looking to stay secure, and in-depth conversations about complex cybersecurity topics.
No gatekeeping and no BS. We’re here to simplify.
Official Website: www.revealrisk.com
LinkedIn: https://www.linkedin.com/company/reveal-risk
🤘 Stay Secure with Us
If this content helped you understand cybersecurity better, please give it a thumbs up, subscribe to our channel for more expert insights, and hit the notification bell so you don't miss our latest updates.
Reveal Risk delivers cybersecurity results, not just reports.
Send us Fan Mail
What happens when military intelligence meets professional sports? Our guest, Jack Thompson, Director of InfoSec, Risk, and Compliance at the Indianapolis Colts, brings a unique perspective to cybersecurity in the high-stakes world of professional football. With a career that transitioned from military operations to safeguarding invaluable sports data, Jack's journey underscores the critical importance of Business Continuity Planning (BCP) and Disaster Recovery (DR). We unpack the constant threats to sensitive information like playbooks and scouting reports, and how advanced data analytics are changing the competitive landscape. Jack's experience offers a compelling lens through which we explore historical incidents like Spygate and the ongoing efforts to protect strategic assets.🔗 Connect with Us & Get in Touch
Tune in to Simplifying Cyber wherever you get your podcasts, or watch exclusive video content right here on the channel. Subscribe for hot takes on emerging technologies, tips and tricks for everyone looking to stay secure, and in-depth conversations about complex cybersecurity topics.
No gatekeeping and no BS. We’re here to simplify.
Official Website: www.revealrisk.com
LinkedIn: https://www.linkedin.com/company/reveal-risk
🤘 Stay Secure with Us
If this content helped you understand cybersecurity better, please give it a thumbs up, subscribe to our channel for more expert insights, and hit the notification bell so you don't miss our latest updates.
Reveal Risk delivers cybersecurity results, not just reports.
Send us Fan Mail
What if understanding human behavior could be the key to bolstering your organization's cybersecurity? Join us for an enlightening conversation with Bob Casey, a veteran security expert whose career has spanned the FBI, Houston Police Department, and corporate security at a major pharmaceutical company. Bob's journey from handling organized crime on the midnight beat in Houston to transforming the FBI's intelligence capabilities post-9/11 is packed with lessons and insights that every threat intelligence analyst needs to hear.
Discover the critical importance of integrating physical and cybersecurity through a cyclical approach to intelligence and security. Bob delves into the human elements behind cyber threats, discussing insider threats, intellectual property protection, and the interplay between cyber attacks and human behavior. His real-life example of a Texas firm's cyber intrusion underscores the necessity of continuous employee education and cybersecurity vigilance, offering a sobering reminder that overconfidence can lead to significant vulnerabilities.
To wrap it all up, Bob shares some of his most memorable encounters with historical figures, including an intriguing story about briefing former President George W. Bush. From advice for aspiring cybersecurity professionals to personal reflections on significant historical moments, this episode is filled with fascinating anecdotes and crucial advice. Whether you're looking to build a career in cybersecurity or simply want to understand the complex world of modern security challenges, you won't want to miss this captivating episode!
🔗 Connect with Us & Get in Touch
Tune in to Simplifying Cyber wherever you get your podcasts, or watch exclusive video content right here on the channel. Subscribe for hot takes on emerging technologies, tips and tricks for everyone looking to stay secure, and in-depth conversations about complex cybersecurity topics.
No gatekeeping and no BS. We’re here to simplify.
Official Website: www.revealrisk.com
LinkedIn: https://www.linkedin.com/company/reveal-risk
🤘 Stay Secure with Us
If this content helped you understand cybersecurity better, please give it a thumbs up, subscribe to our channel for more expert insights, and hit the notification bell so you don't miss our latest updates.
Reveal Risk delivers cybersecurity results, not just reports.
Send us Fan Mail
Ever feel like you're just checking boxes when it comes to cyber awareness training? Prepare to revolutionize your approach as Aaron Pritz, Cody Rivers, and special guest Jim Wailes dissect the urgent need for a cyber education metamorphosis. It's time to transform passive training into a vibrant culture of proactive defense, where every employee is an empowered guardian against digital threats. We're scrapping the obsolete methods and giving you the ABCD blueprint—Awareness, Behavior, Cultural Change, and Delta—to ensure your organization becomes a bastion of cyber resilience.
This episode isn't just a discussion; it's a masterclass in erecting a robust cyber awareness program. We unpack the importance of executive endorsement, pinpointing the ideal advocates, and crafting a plan that transcends the initial rollout's excitement. Jim enlightens us with the harsh realities of cyber strategy missteps and the golden nuggets of incentivizing team engagement. If your aim is to forge a formidable cyber team equipped to navigate the ever-shifting cyber threat terrain, let us arm you with the latest and greatest strategies to protect your digital domain.
🔗 Connect with Us & Get in Touch
Tune in to Simplifying Cyber wherever you get your podcasts, or watch exclusive video content right here on the channel. Subscribe for hot takes on emerging technologies, tips and tricks for everyone looking to stay secure, and in-depth conversations about complex cybersecurity topics.
No gatekeeping and no BS. We’re here to simplify.
Official Website: www.revealrisk.com
LinkedIn: https://www.linkedin.com/company/reveal-risk
🤘 Stay Secure with Us
If this content helped you understand cybersecurity better, please give it a thumbs up, subscribe to our channel for more expert insights, and hit the notification bell so you don't miss our latest updates.
Reveal Risk delivers cybersecurity results, not just reports.
From the publisher's feed
This show features an interactive discussion, expert hosts, and guests focused on solving cyber security and privacy challenges in innovative and creative ways. Our goal is for our audience to…

8,054 Listeners

10,186 Listeners