The Virtual CISO Moment

The Virtual CISO Moment

By Greg SchafferTechnology
Download on the App Store

The Virtual CISO Moment episodes

  • S8E15 – The Modern vCISO Journey with Joseph Gunnells

    What does it really take to evolve into a modern vCISO—and why does it matter more than ever? In this episode, Joseph Gunnells shares his journey from early technical roles to a strategic governance, risk, and compliance leader, revealing how real-world experience—not just certifications—shapes effective security leadership. He breaks down the biggest challenges organizations face when engaging a vCISO, why empathy and business alignment are critical, and how strong relationships can define both career success and cybersecurity outcomes.

    Whether you're an IT leader, aspiring vCISO, or business executive trying to make sense of security risk, this conversation offers practical insights you can immediately apply to better align security with business value—and avoid the common pitfalls many organizations still struggle with today.

    37 min
  • S8E14 - The Reality of Starting a Cyber Business with Robert Duchesne

    From firefighter aspirations to securing the defense industrial base—this episode of The Virtual CISO Moment dives into a career path that didn’t follow the plan… and turned out better because of it.

    Robert Duchesne shares how a pivot from the Air Force into cybersecurity led him to supporting national security missions, leading enterprise security operations, and ultimately launching RD3 Technologies. Along the way, he breaks down the realities of building a cybersecurity business, the difference between government and corporate risk mindsets, and why passion—not paychecks—has to be the driving force in this field.

    We also get into what it really takes to succeed in cybersecurity today: constant learning, understanding the business, and becoming a trusted advisor—not just a technical expert.

    If you’re navigating your own path in cybersecurity or thinking about starting something of your own, this is an episode you won’t want to miss.

    38 min
  • S8E13 - Smarter Security, Fewer Tools with Jason Makevich

    In this episode of The Virtual CISO Moment, Jason Makevich shares his journey from MSP roots to building Greenlight Cyber and PORT1, along with his mission to simplify cybersecurity for SMBs.

    He unpacks the problem of “duct tape on duct tape” security—where too many tools create complexity without real protection—and makes the case for a secure-by-design, zero trust approach. The conversation also covers how SMBs can shift from reactive to proactive security and why translating cyber risk into business terms is critical.

    Jason closes with his perspective on the evolving MSP landscape, warning against chasing trends like AI at the expense of foundational security, and emphasizing the importance of balance in a high-stress industry.

    33 min
  • S8E12 - Winning the AI Job Market with Angelle Ferrer

    Most cybersecurity professionals don’t have a talent problem—they have a visibility problem.

    In this episode of The Virtual CISO Moment, Greg Schaffer sits down with Angelle Ferrer to unpack why even highly qualified professionals are struggling to get noticed in today’s AI-driven job market. From ghosting and overloaded applicant systems to the hidden power of personal branding and storytelling, Angelle shares practical strategies to help you stand out, communicate your value, and actually get hired.

    If you’ve ever felt invisible despite your experience—or wondered why sending hundreds of resumes isn’t working—this conversation will change how you approach your career.

    37 min
  • S8E11 - Cyber Threat Intelligence Insights with Travis Whitesel

    Cybersecurity isn’t just about technology—it’s about mindset, risk, and understanding where organizations are truly vulnerable. In this episode of The Virtual CISO Moment, host Greg Schaffer sits down with cyber threat intelligence professional Travis Whitesel to explore the evolving intersection of military intelligence, cybersecurity, and emerging risks in unexpected places like the sports industry.


    Travis shares how his journey from Army intelligence analyst to cyber warfare technician shaped his approach to cybersecurity—and how that perspective led him to launch Victory Cybersecurity Consulting to help underserved sectors strengthen their defenses within real-world budget constraints. From the growing risks around NIL deals for college athletes to the challenge small organizations face in prioritizing security investments, the conversation highlights practical ways to think about cyber risk without enterprise-level resources.


    The episode also dives into the realities of nation-state threats, why process often matters more than technology, and how cybersecurity professionals can avoid burnout in a high-pressure field. It’s a candid discussion about bridging strategy and tactics, communicating cyber risk in language executives understand, and finding balance while working in one of the most demanding industries today.


    Tune in to hear how one cyber professional is helping organizations—from universities to sports programs—build smarter security strategies in an increasingly complex threat landscape.

    35 min
  • S8E10 - AI Governance and the Future of Security with Jack Rumbaugh

    Cybersecurity leaders often struggle to translate technical risk into something the business actually understands. In this episode of The Virtual CISO Moment, Greg Schaffer sits down with Jack Rumbaugh, an experienced CISO and virtual CISO with a background spanning telecommunications, healthcare, finance, and global enterprises.


    Jack shares how security leaders can communicate cyber risk in the language executives understand—dollars and business impact—using approaches like FAIR risk analysis. The conversation also explores the growing role of AI governance, the risks of relying too heavily on generative AI in development, and why organizations must keep a human in the loop as AI capabilities expand.


    If you're navigating the intersection of cybersecurity, business leadership, and emerging AI risks, this episode offers practical insights you won’t want to miss.

    30 min
  • S8E9 - Jeremy Krienke on Risk, Resilience, and vCISO Work

    Jeremy Krienke, founder and CEO of Sidewalk Security Advisors, shares his journey from early threat intelligence work alongside federal partners to leading security programs in banking and fintech—and ultimately launching his own advisory firm.

    In this episode, Jeremy and Greg explore what it really means to serve as a fractional CISO, how to uncover and align to a company’s true risk appetite, and why many organizations misunderstand executive-level security leadership. Jeremy also discusses the entrepreneurial leap, lessons learned in the first year of business ownership, and his vision for improving third-party risk and incident transparency in regulated industries.

    A candid conversation about strategy, storytelling, and building security programs that actually fit the business.

    32 min
  • S8E8 - Ransomware Realities with Chris Kimpland

    In this episode of The Virtual CISO Moment, Greg Schaffer sits down with Chris Kimpland, CEO of Velocity Incident Response, a service-disabled veteran-owned firm specializing in digital forensics and incident response


    A former U.S. Army combat engineer, Chris has led hundreds of ransomware negotiations and brings a candid, frontline perspective to what unfolds during an active breach. He shares why negotiation is often more business than emotion, what “proof of life” means in a data extortion case, and how organizations navigate the hardest decision of all — whether to pay.


    This episode delivers a concise, real-world look at crisis leadership when minutes matter and stakes are high.

    31 min
  • S8E7 - Governing the AI Explosion with Dr. Natalia Semenova

    In this episode of The Virtual CISO Moment, Greg Schaffer sits down with cybersecurity architect Dr. Natalia Semenova for a deep dive into the evolving world of AI risk and security architecture


    With a Ph.D. in applied mathematics and experience spanning Google, Microsoft, Mercedes-Benz, and Deloitte, Natalia shares how her mathematical mindset shapes her approach to threat modeling, agentic AI, and governance frameworks. The conversation explores:

    • Why AI threat modeling is fundamentally about subjects and objects
    • What ISO 42001 gets right about AI governance
    • How AI risk differs from traditional IT risk
    • Why smaller businesses shouldn’t ignore AI governance
    • The real role (and limits) of the virtual CISO
    • Whether generative AI is eliminating security jobs—or creating new ones

    Natalia also offers a powerful perspective on auditing: if you’re being audited, you should understand the auditor’s playbook.


    If you’re navigating AI adoption, compliance, or evolving your vCISO practice, this episode delivers practical insights grounded in global experience.

    32 min
  • S8E6 - Passing Audits Isn’t Security with Mariia Erokhina

    What does real security maturity actually look like—beyond checklists and audits?


    In this episode of The Virtual CISO Moment, Greg Schaffer sits down with Mariia Erokhina, a global security leader who challenges the industry’s obsession with controls and compliance theater. Mariia shares why security must be embedded into business operations, how executives misunderstand risk ownership, and what aspiring CISOs must learn to operate at the strategic level.


    If you’ve ever questioned whether “audit-ready” really means “secure,” this conversation is for you.

    34 min

About The Virtual CISO Moment

From the publisher's feed

The Virtual CISO Moment dives into the stories of information security, information technology, and risk management pros; what drives them and what makes them successful while helping small and midsized business (SMB) security needs. No frills, no glamour, no transparent whiteboard text, no complex graphics, and no script - just honest discussion of SMB information security risk issues.