Jessica Hoffman

CISO Stories Podcast (Audio)

SC Media is proud to present this month's CISO Stories program, where CISOs share tales from the trenches and unpack leadership lessons learned along the way. Hosted by Jessica Hoffman.

Author

Jessica Hoffman

Category

Technology

Podcast website

www.cisostoriespodcast.com

Latest episode

Jun 8, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Developing Secure Agile Code Quickly is Very Achievable! - Glenn Kapetansky - CSP #26 20.07.2021

Speed to market is the mantra of software development today. This does not mean that a process is not followed, it means that an iterative approach to software development produces code changes and usable code much faster. Join this podcast to learn how security can be imbedded into agile software development to produced fast and secure code.   To view the article from the CISO COMPASS Book that s...

Protecting the "Crown Jewels" - Steve Durbin - CSP #25 13.07.2021

The crown jewels are those assets representing the highest value to the organization and deserve the greatest investment to protect. Join this podcast to learn the importance of protecting these crown jewels throughout the information life cycle. To view the article from the CISO COMPASS Book that sparked this interview, please visit: https://securityweekly.com/wp-content/uploads/2021/04/CISOCOMPA...

CISOs: Always be a Student, Always be Learning - Phil Attfield - CSP #24 06.07.2021

Phil Attfield, CEO and founder at Sequitur Labs, discusses his engineering roots and curius nature that led him to developing software tools and in-house products for modeling, synthesis and verification of telecom and network equipment hardware at Nortel. Phil the challenges involved in development of large-scale security policy and management frameworks and the key security elements of the IoT d...

CISO Business Enablement: Getting to 'Yes' as a CISO - Dan Lohrmann - CSP #23 29.06.2021

The CISO is often in a position where vulnerabilities are known and implementing a product may result in an insecure product. Should the CISO say 'no we can't do that', or 'figure out how to make it happen?' Join this podcast to learn how a CISO was faced with this dilemma where he was asked by the business to implement a technology, where he had stacks of whitepapers indicating the technology was...

Want to Elevate CyberSecurity? Relationships Matter! - Mark Weatherford - CSP #22 22.06.2021

Communication in any organization can be a challenge, especially when working with different levels of government and the various funding mechanisms. Join this podcast to lean how one State CISO navigated the rough waters by focusing on relationships and increased security spending and knowledge of security activities across government levels.   To view the article from the CISO COMPASS Book that...

Fixing the Talent Shortage: CyberSecurity Talent Initiative - Alexander Niejelow - CSP #21 15.06.2021

As threats to the nation's security grow, there remains a substantial and increasing shortage of skilled cybersecurity professionals. The federal government and private sector can work together to fill their open positions and attract the next generation of motivated mission-driven cybersecurity leaders. This podcast discusses the Cybersecurity Talent Initiative, a federal/private partnership whic...

So You Want to be a Cyber Spy? - Ira Winkler - CSP #20 08.06.2021

Ira Winkler, CISO at Skyline Technology Solutions, recounts his amazing journey from wannabe astronaught to NSA intelligence analyst, social engineer, systems hacker and author and some of the crazy things that happened along the way. Ira is considered one of the world's most influential security professionals and has been named a "Modern Day James Bond" - a title he earned by performing espionage...

No Insider Cybersecurity Risk? Guess Again! - Dawn Cappelli - CSP #19 01.06.2021

We want to trust our employees and contractors working within our organizations. For the most part, people are doing their jobs with integrity every day. What happens when an employee decides to leave the organization and start their own business – with our Intellectual property or customer lists? Or when an employee downloads material to work at home? Join this podcast to learn how to build an in...

CISOs Cross the Bridge to the Cloud - Jim Reavis - CSP #18 25.05.2021

Today most organizations have some of the processing in the cloud. As data moves farther away from the physical control of the organization, this movement provides opportunities of scale, flexibility, and speed. Join this podcast to learn how to use appropriate controls to manage this cloud environment.   To view the article from the CISO COMPASS Book that sparked this interview, please visit: htt...

Just Fix It: 5 Critical Elements to Protect the Right Assets - Roland Cloutier - CSP #17 18.05.2021

We have limited investment dollars and therefore must ensure we are protecting the right assets. The practical side of determining "what" needs to be protected and "how" is a convoluted maze of academics, taxonomies, frameworks, and inconsistent approaches. Here we discuss 5 critical elements to make a difference by developing and effective Critical Asset Protection Program (CAPP).   To view the a...

Passion for Solving Problems is Key to Security - Will Lin - CSP #16 11.05.2021

Will Lin, founding team member at ForgePoint Capital and co-creator of the CISO community Security Tinkerers, discusses his passion for technology and how it led him to a career helping security companies launch, as well as his work supporting CISOs through collaboration and knowledge sharing.   Show Notes: https://securityweekly.com/csp16 This segment is sponsored by Cybereason. Visit https://www...

Effective Health Care Security is More Than HIPAA!! - Erik Decker - CSP #15 04.05.2021

Healthcare security today is much more complex with integrated clinical systems and connected community networks. No longer are the medical records stored with a single provider. Join this podcast to learn how one Healthcare CISO is forging relationships and having the appropriate risk-based discussions at the right levels to address the challenge.    To view the article from the CISO COMPASS Book...

Stop Reporting Useless Security Metrics!! - Edward Marchewka - CSP #14 27.04.2021

All disciplines need to be able to demonstrate added value and track the ability to improve upon the current practices. The board, technical management, auditors, and engineers may each need a different view of the security initiatives performed. Join this podcast to how different metrics can be applied to different groups so each can improve their performance over time. To view the article from t...

Necessity is the Mother of Security - Tatu Ylonen - CSP #13 20.04.2021

Tatu Ylönen, SSH founder and inventor of Secure Shell, discusses the genesis for the protocol and his keen interest in the application of technological solutions to fundamental cybersecurity challenges...   Show Notes: https://securityweekly.com/csp13 This segment is sponsored by Cybereason. Visit https://www.cybereason.com/cisostories to learn more about them!   Visit https://securityweekly.com/c...

He Fought the FTC Over a Breach & Won - Michael Daugherty - CSP #12 13.04.2021

Hopefully you won't have to hire a lawyer to defend yourself against a government regulator. What happens when the Federal Trade Commission or other powerful body accuses your company of wrongdoing which you do not feel you were responsible for? Join this podcast and hear how the owner of a small company decided to take on the FTC and how he went about choosing a lawyer. The answers will surprise...

Is There a Magic Security Control List? - Tony Sager - CSP #11 06.04.2021

Never in history has the cyber defender had access to so many technologies and tools to defend our companies. This has created the "Fog of More", making the choices difficult to manage. Join the former 35-year NSA software vulnerability analyst and executive manager, and innovator of community-based controls sharing, as he discusses how the CIS controls can be used effectively to manage our enviro...

Doing Security Before Security Was a Career Path - Petri Kuivala - CSP #10 30.03.2021

Petri Kuivala, CISO at NXP Semiconductors, recounts his journey from municipal police officer to cybercrimes unit investigator to Chief Information Security Officer during the early days when security was largely an afterthought.   Show Notes: https://securityweekly.com/csp10 This segment is sponsored by Cybereason. Visit https://www.cybereason.com/cisostories to learn more about them!   Visit htt...

The Colonoscopy of CyberSecurity - Lee Parrish - CSP #9 23.03.2021

The information and cybersecurity industry have no shortage of regulations and many organizations run down the listing of requirements, load them into an excel spreadsheet to demonstrate compliance. Is compliance the same as security? Join this podcast for an analogy of why compliance is not security and how we can change our organization's orientation to increasing security.   To view the article...

Going All-in on a Career in Security - Mauro Israel - CSP #8 16.03.2021

Mauro Israel, CISO at ORPEA Group, discusses his colorful background and how he - like so many others in the security field - came to discover his true calling late in life but was able to apply his wide range of knowledge and experience to the role of CISO in the healthcare field.   Show Notes: https://securityweekly.com/csp8 This segment is sponsored by Cybereason. Visit https://www.cybereason.c...

Is CyberSecurity ROI Necessary? - Paul Hypki - CSP #7 09.03.2021

Information security departments are often challenged to come up with "ROI" or Return on Investment for the information security initiatives. Why should the information security department be any different? Join this podcast and learn why calculating an ROI may not be necessary and how reducing risk has different considerations.   To view the article from the CISO COMPASS Book that sparked this in...

Your Job is to Make CyberSecurity Simple! - Steve Katz - CSP #6 02.03.2021

The CISO role in some organizations is relatively new. The CISO role has actually evolved over the past 25 years since Citibank named the first CISO. Join this podcast to learn how Steve navigated the early days of security and the changes in the role today.   To view the article from the CISO COMPASS Book that sparked this interview, please visit: https://securityweekly.com/wp-content/uploads/202...

...and Other Useless Security Constructs - Robert Bigman - CSP #5 23.02.2021

Bob Bigman, former CISO for the CIA, simplifies the conversation by slaughtering some of the industry's most sacred cows like risk tolerance as a key driver for security programs...   Show Notes: https://securityweekly.com/csp5 This segment is sponsored by Cybereason. Visit https://www.cybereason.com/cisostories to learn more about them!   Visit https://securityweekly.com/csp for all the latest ep...

Without Building CISO EQ, You May be on Your Own! - Marci McCarthy - CSP #4 16.02.2021

The CISO must interact with many different groups within the company. These groups differ in the amount of business acumen and technical depth necessary. The CISO must have self-awareness of how to approach each of these different types of stakeholders, as well as ensuring appropriate self-care is taken to limit burnout, stress and anxiety. Join this podcast to learn how to maintain appropriate se...

Doing Privacy Right vs. Doing Privacy Rights - Valerie Lyons - CSP #3 11.02.2021

Eric Schmidt (CEO Google 2001-2007) famously noted that his company's policy was to get 'right up to the creepy line and not cross it.' The closer an organization can get to this imaginary line, the greater the profit maximization. When does this become an invasion of privacy? Organizations need to be conscious of where they are in reference to the 'creepy line.' Join this podcast to learn how to...

Sled Security: Pandemics, Policies, & Penny-Pinching - Ari Schwartz - CSP #2 10.02.2021

The Cybersecurity Coalition's Ari Schwartz brings us up to date on some of the organization's initiatives and then dives into some of the challenges SLED defenders are facing in trying to do more with less...   Show Notes: https://securityweekly.com/csp2 This segment is sponsored by Cybereason. Visit https://www.cybereason.com/cisostories to learn more about them!   Visit https://securityweekly.co...

Listen to the CISO Stories Podcast (Audio) podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.