Jessica Hoffman
CISO Stories Podcast (Audio)
SC Media is proud to present this month's CISO Stories program, where CISOs share tales from the trenches and unpack leadership lessons learned along the way. Hosted by Jessica Hoffman.
Author
Jessica Hoffman
Category
Podcast website
Latest episode
Jun 8, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Privacy Hunger Games: Change The Rules - Samantha Thomas - CSP #51 04.01.2022 23:27
Information is meant to be shared with others- others that is with a need to know. CISOs may find that their organization is sharing with other entities without proper procedures in place. What if there are 90 of these organizations? Join this podcast to learn from a healthcare CISO who tackled this dilemma and subsequently changed a government law! To view the article from the CISO COMPASS Book...
Server Room to War Room: Enterprise Incident Response - Dawn-Marie Hutchinson - CSP #50 28.12.2021 28:50
In many organizations, the CISO will be looked at as the leading expert in incident response, but often has little involvement in the selection, planning, and training for the Enterprise Incident Management Program. Listen to Dawn-Marie, who has navigated organizations as a CISO during crisis and consultant to "play like you practice." To view the article from the CISO COMPASS Book that sparked...
CISO Shortlist: Key Issues to Cover for Todays CISOs - Leon Ravenna - CSP #49 21.12.2021 28:14
As if CISOs don't have enough to focus on, here's a few more items that should be top of mind – KAR Global CISO, Leon Ravenna, dives into Cyber Insurance and why D&O requirements may be on the horizon, regulatory burdens and what to expect out of the US Government, how the intersection of Security and Privacy is impacting CISOs, and a little security buzzword bingo and how to deal with the latest...
The Future Is Now: Model-Driven Security Using Data Science - Jim Routh - CSP #48 14.12.2021 27:29
Cybersecurity talent shortages are well documented and asking experience cybersecurity professionals to spend countless hours on routine tasks does not promote retention. The adversaries are leveraging data science to attack our enterprises and consumers, and we need to find a better way. This session explores the experience of creating over 300 models using data science, machine learning, and aut...
CISOs Need Training Too! - Candy Alexander - CSP #47 07.12.2021 25:34
The CISO has trained the workforce and completed the security awareness month annual training. Well, done! Is training done for the year? No. But what about the CISO? How does the CISO ensure that the proper skills are maintained for the CISO to be able to continue to lead the security organization? Join this podcast to learn from the multiple term-elected ISSA International President. To view t...
No Senior Management Buy-in, No Success - Chris Apgar - CSP #46 30.11.2021 24:25
Are you reporting the same risks each year to management? This may be indicative of a lack of incentive or buy-in from senior management to fund the investments. Join this podcast to learn how to show senior management that funding these initiatives is more than risk avoidance and a cost to the bottom line. To view the article from the CISO COMPASS Book that sparked this interview, please visit:...
Skills I Needed to be a First-Time CISO - Richard Kaufmann - CSP #45 23.11.2021 23:35
Infosec skills don't necessarily transfer to CISO skills, but CISO skills are 100% transferable to whatever your infosec career looks like. Growth begins outside of your comfort zones, so some of the CISO skills you can work on now include executive storytelling, internal coalition building, and how to be comfortable being uncomfortable… Show Notes: https://securityweekly.com/csp45 This segment...
Which Approach Wins: Compliance or Risk? - Mark Burnette - CSP #44 16.11.2021 23:19
Cybersecurity programs have evolved from the early days of compliance with regulations. Regulations are important and provide the necessary motivation for many organizations to implement security controls that may not otherwise be present, but is this enough? Is it really security? Join this podcast as the differences between compliance and true security are discussed. To view the article from t...
Who Is Your SOC Really For? - Ricardo Lafosse - CSP #43 09.11.2021 30:40
Managing the volume of security events and continuous threat intelligence can be daunting for the largest of organizations. How do you increase the effectiveness of a Security Operations Center (SOC) and share this information across the organization for greater efficiency and adoption? To view the article from the CISO COMPASS Book that sparked this interview, please visit: https://securityweek...
Do You Know where Your Data Is? - William Miaoulis - CSP #42 02.11.2021 25:54
Data is everywhere today as users are working remotely, storing information in the cloud, downloading to USB drives and so on. Join this podcast to learn from a Healthcare CISO and some of the typical common events which take place to expose sensitive information. To view the article from the CISO COMPASS Book that sparked this interview, please visit: https://securityweekly.com/wp-content/uploa...
The Nexus of Security, Privacy and Trust - Allison Miller - CSP #41 26.10.2021 22:44
Allison Miller, CISO at Reddit, discusses the challenges across stakeholders from end-users to service providers in addressing the nexus of Security, Privacy and Trust? Should they be equally weighted? In what circumstances does the need for one outweigh the need for the others? What does the future hold for our efforts to find the right balance between them? Show Notes: https://securityweekly.c...
5 Pitfalls Issuing Information Security & Privacy Policies - Charles Cresson Wood - CSP #40 19.10.2021 29:52
The interviewee created the landmark 'gold standard' policy guidance in the book Information Security Policies Made Easy, now in its 13th version, and has extensively researched and helped organizations develop relevant policies. This podcast discusses the 5 key mistakes individuals make in creating and delivering policies to the organization. To view the article from the CISO COMPASS Book that...
45 Minutes and 10,000 Servers Encrypted (NotPetya) - Todd Inskeep - CSP #39 12.10.2021 23:11
Learn how to prepare and reduce the risk of the next ransomware event. The guest walks through the lessons learned after managing out of a NotPetya ransomware attack. Will you be ready? Don't miss this podcast for valuable insights from a real-life scenario. To view the article from the CISO COMPASS Book that sparked this interview, please visit: https://securityweekly.com/wp-content/uploads/202...
Security Awareness That Works! - Steven Lentz - CSP #38 05.10.2021 24:20
October is Security Awareness Month! Security Awareness programs must grab the employee's attention if they are to succeed. Join the interviewee as he explains how he successfully engaged the workforce through creative and visible security awareness methods! To view the article from the CISO COMPASS Book that sparked this interview, please visit: https://securityweekly.com/wp-content/uploads/202...
Extending Detection and Response to the Cloud - Kathy Wang - CSP #37 28.09.2021 23:02
Kathy Wang, CISO at Very Good Security, discusses challenges in extending detection and response capabilities to cloud deployments while also ensuring correlations across traditional networks, endpoints, mobile, and user identities. She explains how managing multi-cloud deployments impact this approach, and how organizations can ensure they have the visibility required to detect and remediate earl...
Security from Scratch: Incident Response on a Shoestring Budget - Sam Monasteri - CSP #36 21.09.2021 24:11
Every organization must be able to respond to an attack quickly. Join this podcast to learn key steps to implement in an incident response plan without breaking the bank. Sam approaches this issue by simplifying incident response into the 3 'P's. To view the article from the CISO COMPASS Book that sparked this interview, please visit: https://securityweekly.com/wp-content/uploads/2021/07/CISOSTO...
Fiscally Responsible Ways to Train/Build Community - Kevin Novak - CSP #35 14.09.2021 23:33
All organizations must have security awareness training programs to teach basics to end users. Similarly, the technical teams need to be exposed to flexible training that is interesting to them. Join this podcast to learn how to bring company groups together and form your own DEFCON-type event in-house or in partnership with other organizations. To view the article from the CISO COMPASS Book tha...
Communications Before, During and After the Breach - Melanie Ensign - CSP #34 07.09.2021 22:12
Figuring out what to do after a breach is the wrong time to start the planning process. Communications strategies must be in place well beforehand and there are many benefits to the cybersecurity program for implementing these strategies in advance. Join this podcast to understand how teams benefit from relationships with communication and public relation specialists on their teams. To view the...
The Unpatchable Vulnerability That Is Human Nature - Rachel Tobac - CSP #33 31.08.2021 16:09
Rachel, CEO of SocialProof Security, delves into the inner-workings of social engineering exploits where she leverages her background in neuroscience and behavioral psychology to exploit the unpatchable vulnerability that is human nature. This segment is sponsored by Cybereason. Visit https://www.cybereason.com/cisostories to learn more about them! Visit https://securityweekly.com/csp for all th...
Did You Ask For (and Get!) Too Much Security Money! - James Christiansen - CSP #32 24.08.2021 25:43
It seems CISOs are typically lamenting that the security budgets are insufficient. While this can represent a significant problem in achieving information security goals, what happens when you get the funding you asked for and asked to spend it in less time than expected? Join this session for an investment lesson learned you won't want to miss! To view the article from the CISO COMPASS Book tha...
Practical Considerations for Managing Your MSSP - Johnathan Nguyen-Duy - CSP #31 17.08.2021 21:36
For many organizations, large and small, it would be impractical to "skill up" to manage all aspects of cybersecurity. Managed Security Service Providers provide many different services. Join this podcast to learn how to work with the MSSP to ensure that the organization is obtaining the most value. To view the article from the CISO COMPASS Book that sparked this interview, please visit: https://s...
Achieving Security Buy-in: Change Approach, Not Culture - David Nolan - CSP #30 10.08.2021 22:55
We need the organization to support the cybersecurity initiatives and thus we try to influence the organization to support these goals for the protection of the organizational assets. If we are failing, is it that the organization did not 'get it' or was it our approach? Join this podcast to learn how to achieve that buy-in. To view the article from the CISO COMPASS Book that sparked this intervie...
Hacking Into Cybersecurity - Kerissa Varma - CSP #29 03.08.2021 20:12
Kerissa Varma, Group Chief Information Security Officer of Old Mutual Limited, one of the largest financial services organizations on the African continent, discusses the cybersecurity skills shortage and her initiative to recruit brilliant minds from across an array of fields who have skill sets applicable to cybersecurity, but they might not even know it… This segment is sponsored by Cybereason....
CISO Roundtable: Ransomware Attacks and the True Cost to Business - CSP #28 30.07.2021 58:10
A recent global research report conducted by Cybereason, titled "Ransomware: The True Cost to Business", revealed that the vast majority of organizations that have suffered a ransomware attack have experienced significant impact to the business, including loss of revenue, damage to the organization's brand, unplanned workforce reductions, and little in the way of relief from cyber insurance polici...
10 Min for a Call? Managing the Security Product Salesperson - Kevin Morrison - CSP #27 27.07.2021 22:24
CISOs are approached frequently by salespersons to buy products to reduce risk. How do you manage these relationships? Join this podcast to learn how to respond to the salesperson, reduce time, and select the best products with reduced wasted interaction. To view the article from the CISO COMPASS Book that sparked this interview, please visit: https://securityweekly.com/wp-content/uploads/2021/0...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.