Dejan Kosutic
Secure & Simple — Podcast for Consultants and CISOs on Cybersecurity Governance and Compliance
“Secure & Simple” demystifies governance and compliance challenges faced by CISOs, consultants, and other cybersecurity professionals. The podcast is hosted by Dejan Kosutic, an expert in cybersecurity governance, ISO 27001, NIS2, and DORA. The episodes present topics in an easy-to-understand way and provide you with insight you won’t be able to find elsewhere. To provide comments, suggest topics for the next episodes, or express your interest in participating in the show, contact us at podcast@advisera.com. Learn more about ISO 27001, NIS2, and DORA at https://advisera.com.
No dejes de visitar la web del podcast y apoyar a su creador: advisera.com
Autor
Dejan Kosutic
Categoría
Web del podcast
Último episodio
6 de oct. de 2026
¿Dónde escuchar?
Podcasts en la app Replaio Radio Muy prontoLos podcasts llegarán muy pronto a la app. Instálala ahora y sé el primero en descubrir una forma totalmente nueva de vivir los podcasts
Episodios
Strategic Human Firewall: Overcoming the Human Blind Spot | Interview with Robert Siciliano 06.10.2026 49:26
In this Secure and Simple Podcast episode, host Dejan Kosutic (Advisera) interviews Robert Siciliano, co-founder of ProtectNow and author of Strategic Human Firewall, about why organizations must address the “human blind spot” - people’s psychological need to trust that attackers exploit through impersonation, social engineering, and manufactured urgency. Siciliano explains why phishing simulation...
How to Integrate Security Controls Across ISO 27001, NIST & SOC 2 | Interview with Aron Lange 22.09.2026 45:08
In this episode of Secure and Simple Podcast, host Dejan Kosutic (Advisera) speaks with Aaron Lange (GRC Lab, TÜV SÜD auditor) about combining security controls across multiple standards and frameworks, including ISO 27001/27002, NIST Cybersecurity Framework, NIST SP 800-53 and 800-171, TISAX, C5, SOC 2, and sector-specific regimes like PCI DSS and CMMC. They clarify the difference between require...
Security as a Business Enabler: From Cyber Risk to Action | Interview with Matthew Webster 08.09.2026 39:52
Dejan Kosutic hosts Matthew Webster, founder and CEO of Cyvergence, to explain what “security as a business enabler” means in practice: aligning cybersecurity with business operations, priorities, and decision-making rather than siloed technical metrics. Webster emphasizes using business impact analysis, scenario analysis, and cost-benefit thinking to translate vulnerabilities into operational ris...
Positive Reinforcement & Gamified Security Awareness | Interview with Craig Taylor 25.08.2026 44:15
In this episode of the Secure and Simple Podcast, host Dejan Kosutic (CEO at Advisera) interviews Craig Taylor, CEO and co-founder of CyberHoots, about best practices and myths in cybersecurity awareness training. Taylor argues the industry’s biggest mistake is relying on punishment, shame, and deception-based phishing tests, saying psychology supports positive reinforcement and rewards to increas...
CMMC Level 2: Documentation, Costs, and Audit Readiness | Interview with Bruno Lecoq 10.08.2026 41:08
Dejan Kosutic hosts Bruno Lecoq (co-founder, CEO, and CISO at BEMO) to explain CMMC compliance for Department of Defense contractors and suppliers, including those outside the U.S. They cover CMMC basics (levels, CUI vs. FCI, C3PAO assessments, phase 1 boundary review and phase 2 audit), current capacity challenges (about 93 C3PAOs vs. roughly 200,000 contractors), and why many companies fail earl...
Securing the Agentic Enterprise | Interview with Charlie Lewis 28.07.2026 48:00
Host Dejan Kosutic interviews McKinsey & Co. partner Charlie Lewis about how agentic AI will reshape cybersecurity by reinventing existing categories — especially identity, detection, operations, and vulnerability management — rather than creating entirely new ones. Lewis argues every company will manage a massive digital workforce of dynamically created, short-lived agents with constantly cha...
How Hackers Exploit Human Bias and Technical Weaknesses | Interview with Kevin Beaver 14.07.2026 45:37
In this Secure and Simple Podcast episode, host Dejan Kosutic interviews independent information security consultant and Hacking for Dummies author Kevin Beaver about how hackers are often underestimated and how many run operations like a professional business. Beaver explains psychology concepts that affect security decisions, including the Dunning-Kruger effect, sunk cost fallacy, bystander apat...
How CISOs Should Talk to Corporate Boards | Interview with Michelle Drolet 30.06.2026 41:47
In this Secure and Simple Podcast episode, host Dejan Kosutic (Advisera) interviews Michelle Drolet, CEO and founder of Towerwall, about communicating cybersecurity to corporate boards. Drolet says boards often don’t know what questions to ask, so CISOs should drive the agenda by focusing on incident impact, business risk, and alignment to strategic initiatives rather than vulnerabilities or techn...
Why Conventional Cybersecurity Won’t Protect AI? | Interview with Hugo Huang 16.06.2026 42:50
In this Secure & Simple Podcast episode, host Dejan Kosutic (Advisera) talks with Hugo Huang, Product Director at Canonical and author of a Harvard Business Review article, about why conventional cybersecurity tools and patching alone are insufficient for AI systems. Huang shares research conducted with Canonical, IDC, and Google Cloud, highlighting leaders’ concerns about shadow AI usage, opa...
ISO 27001 Certification: What Will the Auditor Look For? | Interview with Aron Lange 02.06.2026 37:51
In this Secure & Simple Podcast episode, host Dejan Kosutic (CEO of Advisera) interviews Aron Lange, founder of GRC Lab and an ISO 27001 certification auditor, about what auditors look for in certification audits. Aron highlights common nonconformities and explains how auditors gather objective evidence through interviews, document review, and observation, emphasizing execution over paperwork....
Anthropic’s Mythos and the Future of Vulnerability Management | Interview with Thom Langford 19.05.2026 41:25
In this Secure and Simple Podcast episode, host Dejan Kosutic (CEO at Advisera) speaks with Thom Langford, CTO for the EMEA region at Rapid7, about Anthropic’s new AI model “Mythos” and its impact on cybersecurity. Langford argues that the fundamentals remain the same - discover, risk-contextualize, and patch - but the speed, scale, and volume of findings will surge, exposing immature vulnerabilit...
What CISOs Must Do Now About Quantum? | Interview with Andrew Gault 05.05.2026 43:43
In this Secure and Simple Podcast episode, host Dejan Kosutic (CEO of Advisera) interviews Andrew Gault (CEO of ZeroTier) about how quantum computing could impact cybersecurity, especially encryption and identity. They explain key terms like post-quantum cryptography (PQC), Q-Day, cryptographically relevant quantum computers, and main threats, “harvest now, decrypt later” and “trust now, forge lat...
Continual Improvement, Nonconformities, and Corrective Actions | Interview with Carlos Cruz 21.04.2026 56:00
In this Secure and Simple Podcast episode, host Dejan Kosutic from Advisera interviews Carlos Cruz, founder of Metanoia and an ISO 9001/ISO 14001 expert, about continual improvement in ISO standards and how the concepts apply to cybersecurity. They explain continual improvement through the PDCA cycle, using data and Pareto analysis to focus on key issues, then performing root cause analysis with t...
Cyber Ranges, Attack Simulations & AI: Proving Cyber Readiness | Interview with Lee Rossey 07.04.2026 47:03
In this Secure and Simple Podcast episode, host Dejan Kosutic (CEO of Advisera) speaks with Lee Rossey, CTO and co-founder of SimSpace, about why much cybersecurity training is becoming outdated as AI accelerates both threats and defensive stacks. Rossey explains “train like you fight” through realistic, hands-on, team-based cyber range exercises that emulate an organization’s environment, tools,...
AI Agents vs. AI Agents: The Future of Security Operations | Interview with Monzy Merza 24.03.2026 48:47
In this Secure and Simple Podcast episode, host Dejan Kosutic from Advisera interviews Monzy Merza, co-founder and CEO of Crogl, about how cybersecurity is shifting to an “agent versus agent” world where attackers task AI agents to run fast, low-cost, sophisticated campaigns without human approvals. Merza outlines core security operations activities—preparation/tooling, alert investigation, and re...
Zero Trust as a Mindset: Identity, Governance, and Access | Interview with Andrew Gault 10.03.2026 45:46
In this Secure and Simple Podcast episode, host Dejan Kosutic (CEO of Advisera) interviews Andrew Gault (CEO of ZeroTier) about Zero Trust as a strategy and mindset rather than a single technology, shifting away from perimeter-based security to “default deny” with continuous verification. Gault outlines core layers such as identity for users and devices, policy-based scoring, encryption, and ongoi...
Responding to Ransomware Attack [Case Study] | Interview with Yannick Hirt 24.02.2026 42:51
Dejan Kosutic interviews Yannick Hirt from ODCUS about his experience with a real ransomware attack on an international industrial company. They discuss likely phishing entry via a privileged IT account, overnight encryption, and setting up a war room. The company restored critical systems from verified cloud backups without paying, while briefly negotiating via a Dutch specialist as the attacker...
What Should the Board Ask the CISO? | Interview with Clar Rosso 10.02.2026 37:05
In this episode, Dejan Kosutic talks with Clar Rosso, CEO of Rosso Strategic Advisors, board member of Excelsior University, and the former CEO of ISC2, about the evolving role of boards for cybersecurity. They discuss the increasing importance of cyber governance, the impact of AI, the concept of digital resilience, and the interaction between cybersecurity professionals and boards of directors....
The Crucial Role of Management Review in Cybersecurity Governance | Interview with Carlos Cruz 27.01.2026 56:25
In this special first-year anniversary episode of the Secure and Simple Podcast, host Dejan Kosutic from Advisera welcomes back Carlos Cruz, founder of Metanoia Consulting and ISO expert. They deep-dive into best practices for conducting effective management reviews, covering not just ISO 9001 and ISO 14001 but also ISO 27001 and other cybersecurity frameworks. The discussion highlights the import...
Resolving a Conflict Between IT and Cybersecurity | Interview with Jared Leuschen 13.01.2026 41:38
In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO of Advisera, discusses the ongoing conflict between IT operations and cybersecurity governance with Jared Leuschen, CEO and Founder of Blue Tree. They delve into the human component behind security and compliance issues, misalignment and communication gaps within organizations, and practical solutions for aligning IT and cyb...
Penetration Testing & Threat Intelligence: Enhancing Cybersecurity | Interview with Sasa Jusic 30.12.2025 41:34
In this episode, host Dejan Kosutic interviews Sasa Jusic, a board member at Infigo IS and a cybersecurity expert. They delve deep into penetration testing and cyber threat intelligence, explaining their roles in enhancing cybersecurity. Learn about the differences between offensive and defensive security measures, the importance of DORA and ISO 27001 frameworks, the critical steps for preparing a...
Simplifying ISO Standards: Insights and Best Practices | Interview with Jim Moran 16.12.2025 58:01
In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO of Advisera, welcomes Jim Moran, founder of SimplifyISO, to discuss the importance and methods of simplifying ISO management systems. Jim, with over 30 years of consulting experience, shares valuable insights on how overly complex management systems can hinder employee understanding and implementation, leading to higher cost...
Mastering Internal Audits for ISO Standards | Interview with Carlos Cruz 02.12.2025 1:05:55
In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO at Advisera, welcomes Carlos Cruz, founder of Metanoia Consulting and a seasoned expert in ISO standards. Carlos and Dejan share best practices for performing internal audits across various ISO standards, including ISO 27001, and other cybersecurity frameworks such as NIS2 and DORA. Key topics discussed include the importanc...
Exploring Cyber Warfare: Risks, Strategies, and Solutions | Interview with Steve Winterfeld 18.11.2025 53:02
In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO of Advisera, welcomes Steve Winterfeld, a seasoned security consultant, fractional CISO, and author of the book 'Cyber Warfare Techniques, Tactics, and Tools for Security Practitioners.' The discussion revolves around the relevance of cyber warfare for companies, the different types of cyber threats, and strategic ways to ad...
Bridging the Cybersecurity Gap: From Tech Rooms to Boardrooms | Interview with Paul C Dwyer 04.11.2025 50:59
In this episode of the Secure and Simple Podcast, Dejan Kosutic, CEO of Advisera, interviews Paul C Dwyer, founder and CEO of Cyber Risk International and president of the ICTTF. They discuss digital resilience from a business and strategic standpoint, the role of company boards in cybersecurity, and how to effectively bridge the communication gap between technical experts and business leaders. Pa...
Podcasts similares
Replaio no es editor de podcasts; los nombres de los programas, las portadas y el audio pertenecen a sus autores y se distribuyen a través de canales RSS públicos