Jessica Hoffman
CISO Stories Podcast (Audio)
SC Media is proud to present this month's CISO Stories program, where CISOs share tales from the trenches and unpack leadership lessons learned along the way. Hosted by Jessica Hoffman.
Author
Jessica Hoffman
Category
Podcast website
Latest episode
Jun 8, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Achieving a Competitive Advantage Through Privacy By Design - Ann Cavoukian - CSP #76 28.06.2022 22:10
Join the former Privacy Commissioner of Ontario, Canada and creator of PrivacyByDesign (PbD), translated into 40 languages and incorporated into General Data Protection Regulation (GDPR) and used by many organizations to proactively "bake-in" privacy into our systems. Every CISO needs to pay attention to and support the various country privacy laws. To view the article from the CISO COMPASS Book t...
Attracting Talent Using The Nice Framework - Greg Witte - CSP #75 21.06.2022 24:29
As your organization increases the cybersecurity talent to protect and defend the information assets, how do you know what skills are needed? What tasks are to be performed and what knowledge is necessary to perform these functions? The NIST NICE Framework helps define the job and assist the CISO in hiring as well as measuring the capability along the career path. To view the article from the CISO...
Where Should the CISO Report? Guess Again! - Stephen Fried - CSP #74 14.06.2022 26:00
Where the CISO should report has been debated for many years, with the predominant view being "anywhere but the CIO", while even in 2022, most CISOs are reporting to the CIO! Which reporting structure viewpoint is right? This podcast will examine the pros and cons of reporting to the CIO and other departments. Join Stephen as he shares his experience as a Former CISO for several large financial in...
Educating Senior Management in Cybersecurity - Edward Amoroso - CSP #73 07.06.2022 26:42
Managing cybersecurity defense inside an organization is an enormously complex endeavor, considering the interconnections, vendor relationships, cloud, and mobile proliferation of the data. While many of these computing technologies have a clear purpose and usefulness, many times organizations minimize the complexity when presenting to the Board. Should we? Join us as we discuss a different approa...
Moving From a Techie to a CISO - Shaun Cavanaugh - CSP #72 31.05.2022 28:33
Careers can just happen, or they can be planned. Join us as we discuss making the decision to become a CISO and then taking the steps necessary to develop the skills to attain the job and thrive in the role. To view the article from the CISO COMPASS Book that sparked this interview, please visit: https://securityweekly.com/wp-content/uploads/2022/04/CISOSTORIES_ShaunCavanaugh_Article.pdf Cavanaugh...
Women in Leadership - Stacy Mill - CSP #71 24.05.2022 27:14
The cybersecurity field has traditionally been male dominated and there is clearly a desire to attract more women into the field. Join us as we discuss practical tips for women advancement to leadership positions, how to stand apart when climbing the leadership ladder, and advice for leading effective teams. To view the article from the CISO COMPASS Book that sparked this interview, please visit:...
Establishing and Selling The Cost of Cybersecurity - Devon Bryan - CSP #70 17.05.2022 27:43
The security spend is increasing year over year as hackers become more sophisticated, organized, and opportunistic. Join us as we discuss ways to determine and evaluate the cost of cybersecurity to ensure the organization is spending the appropriate amount to reduce the risk to an acceptable level. To view the article from the CISO COMPASS Book that sparked this interview, please visit: https://se...
Deliver Your Board Message with Context and Confidence! - Jason Witty - CSP #69 10.05.2022 22:28
A key function of the CISO is to provide an accurate organizational picture of the risk the organization is currently accepting and communicate the strategy for enhancing the security maturity in support of the business goals. The way you prepare and communicate is just as important as the message. Join us as we discuss how to improve the delivery of the message. To view the article from the CISO...
Using Security Metrics as a Shared Goal With Developers - Caroline Wong - CSP #68 03.05.2022 25:11
Security metrics are often a struggle to establish by security departments. These metrics may be taking too narrow of a view, whereby metrics visible and embraced by other areas can improve the security program success. Join us as we discuss these metrics. Additionally, Caroline is graciously offering her Linkedin metrics course focused on establishing objectives and measuring progress towards the...
Keeping Up with the Jones when Your Neighbors Are Bad Actors - Jason Taule - CSP #67 26.04.2022 25:58
Organizations want to know, how are we doing with respect to security? Companies can accept risks they are aware of, and don't want to outspend the competitors with the industry vertical. They also need a way to understand and benchmark the effectiveness of the security program. Join us as we discuss how to ensure the threats are being evaluated. To view the article from the CISO COMPASS Book th...
Get Ready: 4 Generations Are Returning to The Office! - Caitlin McGaw - CSP #66 19.04.2022 25:45
We have four generations predominantly in the workforce today, boomers, generation X, Millennials, and Generation Z. Each generation was influenced by different world events, shaping values towards work, family, and technology. The past few years have brought a changing view towards work, with remote and hybrid working. Join us as we discuss these challenges. McGaw, C. 2019. Optimizing Four Gene...
Control Frameworks Are There For A Reason - Philip Agcaoili - CSP #65 12.04.2022 32:56
In addition to serving as a CISO for several large companies, Phil was instrumental in co-founding the Cloud Security Alliance (CSA) and creating the Cloud Controls Matrix (CCM) to identify what standards from the many frameworks such as NIST, ISO27000, COBIT, HIPAA, PCIDSS, etc. would be applicable to the cloud environment. Join Phil as he discusses his view of these frameworks and his approach t...
Change Controls Are More Necessary Than Ever - Rebecca Herold - CSP #64 05.04.2022 26:03
Organizations are developing technology at a rapid pace today to maintain business relevance and adapt to changing conditions. Rebecca talks about the importance of ensuring change control is implemented and the real impacts if not implemented correctly. To view the article from the CISO COMPASS Book that sparked this interview, please visit: https://securityweekly.com/wp-content/uploads/2021/12...
Determining Cyber Risk Appetite With the Board - Adel Melek - CSP #63 29.03.2022 30:12
One of the most important and impactful tasks of the CISO is presenting to the Board of Directors and Senior Management. The Board needs to have the confidence the CISO is able to determine risk and provide recommendations of cost-effective business-oriented solutions. Listen to Adel as he shares his experience in working with many organizations to reduce risk. To view the article from the CISO...
CISO Priorities 2022 - CSP #62 22.03.2022 1:02:07
For security leaders, it can be hard to catch a break when faced with the increasingly challenging task of defending their organizations from evolving threats while simultaneously fighting the battle of the budget in an effort to do more with less. What issues should CISOs be prioritizing, and how can they get the most bang for their buck with regard to minimizing potential risks and maximizing po...
Why Are We Still Failing at Security? - Wayman Cummings - CSP #61 15.03.2022 13:23
Why are we failing at security, and will we ever graduate from Cyber-Kindergarten? The industry has arguably made a lot of progress over the last three decades, yet the attackers still enjoy a distinct advantage. Wayman Cummings, VP of Security Operations at Unisys, joins the podcast to discuss how industry stagnation impacts the security for our critical infrastructure when that rises to the leve...
The CISO Six Minute Rule - Renee Stark - CSP #60 08.03.2022 27:02
Sharing sensitive information on a website is likely to solicit a 'No Way" response from the CISO. Renee was faced with these decisions early in her career and needed a way to determine and communicate the right pragmatic and ethical decision. She developed the 'Six-Month Rule", which has evolved into the "Six-Minute Rule" to guide these decisions. Just us as Renee articulates how to help appropri...
Lessons Learned from Building an ISAC - Grant Sewell - CSP #59 01.03.2022 26:50
Information Sharing and Analysis Centers (ISACs) were formed to promote the centralized sharing of threat intelligence within a particular sector. These have grown since the first ISAC in the late 1990's and now represent over 20 industry sectors. Grant shares his experience in working with an ISAC and how this benefited his organization and the broader CISO community. To view the article from t...
Getting the Board on Board With Security - Richard Clarke - CSP #58 22.02.2022 24:58
Richard spent several decades serving Presidents of both parties and understands what is necessary to implement effective security programs. Join us as he provides pragmatic tips for working with the Board of Directors to effectively communicate the investment need and articulate the benefits in terms the Board can support. To view the article from the CISO COMPASS Book that sparked this intervi...
Understanding and Preparing for the Next Log4j - Benny Lakunishok - CSP #57 15.02.2022 23:20
The issues created by the recently disclosed Log4j vulnerability are bigger than you might expect and will have long-lasting implications. So, what was the Log4j vulnerability really, what can be done to reduce the risk it poses to organizations, and how can we better prepare for the next Log4j-level event? Benny Lakunishok, co-founder and CEO of Zero Networks, takes us deeper… Show Notes: https...
A Cost-Effective Approach to Security Risk Management - Jack Jones - CSP #56 08.02.2022 32:28
Risk management is arguably one of the most important functions of the CISO. How does the CISO establish the value proposition for an investment? Using a well-tested risk framework, Jack discusses how to evaluate and compare the current state of loss exposure and the expected reduction from applying a set of alternative controls. To view the article from the CISO COMPASS Book that sparked this i...
Creating Security Budgets Where There is No Budget - Kevin Richards - CSP #55 01.02.2022 26:58
Kevin walks through a very creative method of getting the budget necessary. Over the years, security departments acquire tool after tool, sometimes integrated, and many times under-utilized. Kevin describes how to leverage the current environment to "find" new sources of budget to fund the right cybersecurity investments. To view the article from the CISO COMPASS Book that sparked this interview...
When Should You Just Do It Internally or Hire a Consultant? - John Iatonna - CSP #54 25.01.2022 27:27
With the talent shortage expected to last many years into the future, when a new cybersecurity skill is needed that is available within the current team, what do you do? Should you hire someone externally, or bring in a consultant? What are the pitfalls of each approach? Join John as he discusses his experience in making these tough decisions. To view the article from the CISO COMPASS Book that...
Designing a Shared Vision with IT and the Business - Scott King - CSP #53 18.01.2022 25:30
The locus of control has been slipping away from IT teams (and by default Security teams), and this "challenge" to IT governance has accelerated post-covid with a more distributed workforce. The fact that IT governance is eroding as easily and quickly should tell IT and infosec teams that they need to ditch their legacy models of service delivery and adopt an approach that addresses the current bu...
Moving to the Cloud? Don't Forget Hardware Security! - Steve Orrin - CSP #52 11.01.2022 22:21
While the cloud computing infrastructure is designed to be very agile and flexible, transparency to where the information is being processed is very important due to global privacy and security concerns. Steve discusses approaches to remaining compliant with the various laws (i.e., restricting where the data may reside) when moving to the cloud. To view the article from the CISO COMPASS Book tha...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.