SC Media
CISO Stories Podcast (Video)
SC Media is proud to present this month's CISO Stories program, where CISOs share tales from the trenches and unpack leadership lessons learned along the way. Hosted by Jessica Hoffman.
Author
SC Media
Category
Podcast website
Latest episode
Jun 8, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Identity Security Training: How important is it? - Eric Belardo - CSP #200 Video 12.11.2024 30:32
Let's talk about what CISOs look for when hiring identity and access management team members. What training and experience is most attractive for the business and team. This segment is sponsored by CyberArk. Visit https://cisostoriespodcast.com/cyberark to learn more about them! This segment is sponsored by Saviynt. Please visit https://cisostoriespodcast.com/saviynt to learn more and get a free d...
Have you ever had a pen tester own your network? - Julian Austin - CSP #199 Video 05.11.2024 28:51
Guessing the answer is yes. Well, let's talk about some of the simple ways you can avoid account compromises by strengthening your identity security through MFA, least privilege, account reviews, and all the things! This segment is sponsored by CyberArk. Visit https://cisostoriespodcast.com/cyberark to learn more about them! This segment is sponsored by Saviynt. Please visit https://cisostoriespod...
How important is your relationship with your tool vendors? - Jacob Lorz - CSP #198 Video 29.10.2024 28:38
Let's talk about how important having a customer success manager, or equivalent, to assist you with your tool integration can make the difference between resource fatigue and success. On top of having solid relationships with our tool vendors, long time CISO Jake Lorz, shares with us how important tool interoperability is, proper governance reviews, and looking at your organization's security stra...
What level of tool rationalization does your company do and why? - LaLisha Hurt - CSP #197 Video 22.10.2024 30:36
Let's talk to cybersecurity expert, Lalisha Hurt, about her approach to selecting the right tools for your organization by using proven methods such as referencing the Gartner Magic Quadrant, thinking about the entire IT portfolio as part of your selection process, and what a successful 'Vendor Day' can do! Show Notes: https://cisostoriespodcast.com/csp-197
Have you consider your team's cognitive biases when selecting tools? - Dustin Sachs - CSP #196 Video 15.10.2024 37:26
What if there was more to making those impactful decisions that you haven't considered? Let's talk about how being open minded can directly impact the success of tool selection and optimization in your company. Is a SOC report enough or are there other criteria needed to make that risk based decision? Let's discuss cognitive biases in tool selection with researcher Dr. Dustin about why it benefits...
Tokyo DriftSec: Who is going First? Who is going Smooth? - Lisa Landau - CSP #195 Video 08.10.2024 29:22
Let's talk to our favorite Tokyo security leader about how she has experienced tool selection across the world. To be risk adverse or not to be risk adverse. What a question! Segment Resources: https://www.youtube.com/watch?v=BdFzJxSemKo Show Notes: https://cisostoriespodcast.com/csp-195
What are your pet peeves when it comes to tool selection? - Timothy Ball - CSP #194 Video 01.10.2024 39:58
Hear from expert TimBall, CISO for NGO-ISAC, on his experiences in the industry and how he advises his members on finding the right tool. Especially when it comes to making sure the tool isn't a 'shiny object' purchase but actually addressing your organizations underlying issues and bringing value! Bonus, let's talk about election security! Segment Resources: https://www.ngoisac.org/ Show Notes: h...
Tried and True. Going back to basics with Incident Response - Levone Campbell - CSP #193 Video 24.09.2024 36:13
Let's talk about how regardless of your organizations data footprint being in the cloud or on prem, or if you're a billion dollar organization or smaller, if the adversaries want in, they will find a way. Don't fall victim because of bad cyber hygiene but instead work your experiences, your leadership, and train your people to limit exposure. Hear from Incident Response expert, Levone Campbell, on...
The vCISO's role in Incident Response Accountability - William Klusovsky - CSP #192 Video 17.09.2024 26:02
Let's talk about the vCISO's approach to Incident Response advisory with clients; particularly small and medium sized businesses (SMB). How can your cyber liability insurance support your organization outside of when an incident occurs? We will discuss strategies SMBs can take to strengthen their IR plans while keeping in mind their business needs and contingency plans. Segment Resources: https://...
CISO & Legal: Partnerships Needed - Joe Sullivan - CSP #191 Video 10.09.2024 30:59
Listen to the importance of legal relationships and interaction with the CISO and security program. Jess and Joe talk about the need for legal to understand the security team's day to day and also what incident response means to your organization. Bringing your legal reps into the folds when a breach happens is too late! Work as a team early to make sure all parties are knowledgeable and ready to...
Todd's Moving On after 185+ Episodes - Future CISO Vision - Todd Fitzgerald - CSP #190 Video 03.09.2024 32:48
Todd Fitzgerald will be moving on from the CISO STORIES podcast after 185+ episodes, which was initiated almost 4 years ago following the publication of the #1 Best-Selling CISO COMPASS book, which has guided 1000's of emerging, current, experienced, and new CISOs and their teams in their journey to protect our organizations' and nation's information assets through a structured, business-oriented...
Vulnerability Management: Tips and Techniques - John Kellerhals - CSP #189 Video 27.08.2024 25:08
Vulnerabilities are the 'front doors' for attackers to infiltrate our systems and a key process organizations must get right into order to protect our systems and information assets. Join us as we discuss vulnerability management, identification of assets, prioritization, threat intelligence, leveraging tools, desired vulnerability product features, business impact and vulnerability measurement ti...
Are You Vulnerable to Deep Fakes? Controlling the Risk - Paul Neff - CSP #188 Video 20.08.2024 41:08
Rapid advancement in the sophistication and availability of "deepfake" technology enabled by generative AI - the ability to generate convincing multimedia and interactive representations indistinguishable from the real thing - presents new and growing challenges for CISOs seeking to combat fraud, intrusion, disinformation, and other adverse consequences of social engineering. CISOs will need to ma...
Focus, Breadth, or Depth: Reduce Vulnerabilities with Less $ - Julian Mihai - CSP #187 Video 13.08.2024 26:02
Managing vulnerabilities is a large, complex problem that can't be completely fixed. And still, many cybersecurity organizations continue with a traditional approach that attempts to address all vulnerabilities, spreading staff too thin and increasing exploitation windows. With a small set of vulnerabilities being the cause of most of the breaching, taking a focused approach can have a significant...
No One Succeeds Alone! Why You Must Have an Informal Network - Gene Scriven - CSP #186 Video 06.08.2024 26:58
Join us as we discuss how critically important it is for a CISO to establish, maintain, and frequently leverage in informal network. With almost daily changes in the threat landscape across all industries, it's critical to have informal but trusted resources to rely on for advice, information, and just overall "sounding board" opportunities. Show Notes: https://cisostoriespodcast.com/csp-186
Driving the Business of Infosec Through the GRC Program - Greg Bee - CSP #185 Video 30.07.2024 28:20
Join us as we discuss the organization's GRC program and how GRC helps drive the business of information security from internal and external perspectives to integrate security into the culture, while maintaining compliance with regulations imposed for insurance and public companies. Segment Resources: Webcast: https://www.scmagazine.com/cybercast/the-regulatory-landscape-in-2030-what-you-need-to-k...
Evolving from Security to Trust, more than Just Compliance - Mike Towers - CSP #184 Video 23.07.2024 30:45
CISOs need to enhance their strategic influence and operational impact within their organizations. This calls for a departure from traditional, insular security approaches towards a partnership model that aligns security initiatives with business growth and value. By adopting an attitude of listening, humility, and interdisciplinary collaboration, CISOs can transcend fear-based justifications for...
CISO Risk Reduction: Adopting Emerging Technologies - Timothy McKnight - CSP #183 Video 16.07.2024 33:03
With the vast number of cybersecurity solutions in the marketplace, how do you identify what fits with your company's strategic goals, then deploy and scale in a reasonable timeframe? Hear a CISO who has built a methodology for assessing and implementing new security technologies and successfully used it at several large global enterprises. Segment Resources: Webcast: https://www.scmagazine.com/cy...
Deep Dive in GRC: Know Your Sources - Jonathan Ruf - CSP #182 Video 09.07.2024 30:46
As organizations grow, there comes a time when managing by excel spreadsheets is not longer feasible and accurate data sources, regulations, and risk need to be accurately reflected within Governance, Risk and Compliance (GRC) tools. Reporting to the board must be based upon accurate information. Join us as we discuss the important aspects of forming a GRC program. Segment Resources: Webcast: http...
Governing Cyber Humanely: Leveraging Wellness Techniques - Jothi Dugar - CSP #181 Video 02.07.2024 31:24
We discuss the topic of Human Centric Cybersecurity and the importance of empowering the 'people' aspect of the People, Process, Tech framework. In this conversation we raise the importance of well-being amongst Tech and Cyber leaders and how to keep calm through the chaos to lead our teams well. Also important is diversity in this field and the Holistic approach to cyber, starting with the people...
CISOs Advising Cybersecurity Companies, Get on Board! - Bob West - CSP #180 Video 25.06.2024 28:16
Advisory Boards - helping cybersecurity companies grow is foundational to helping enterprises select best in class tools to protect their environments. If done properly, scaling cybersecurity companies can have a positive global impact on how information is protected and minimizing business disruption. Show Notes: https://cisostoriespodcast.com/csp-180
As We Implement Zero Trust, Let's Not Forget About Metrics - George Finney - CSP #179 Video 18.06.2024 29:10
Many organizations are starting today down the Zero Trust path. Zero Trust is a strategy (vs an architecture) and to prove the value of this investment, we need to start thinking about metrics to demonstrate value. Join us as we discuss some of the metric directions to consider when moving our organizations towards Zero Trust. Show Notes: https://cisostoriespodcast.com/csp-179
CISO and the Board: Demonstrating value and relevant metrics - Max Shier - CSP #178 Video 11.06.2024 30:34
The importance of CISO skills/metrics for the board, demonstrating the business value and necessity of good cybersecurity posture, as capabilities the CISO must master to be effective in securing the appropriate investment level. Join us as we discuss interactions with the board and leveraging metrics to show business value. Show Notes: https://cisostoriespodcast.com/csp-178
Point Vs. Platform: Improving TCO Cost/Benefit - Patrick Benoit - CSP #177 Video 04.06.2024 28:41
CISOs must prioritize the intelligent selection of cybersecurity products by considering the total cost of ownership (TCO) and whether point products or platforms are best suited. This includes the costs of deployment and operations for people, processes, and technology, as well as the ongoing maintenance and support of a product. By considering the TCO of various products, CISOs can make more inf...
Data Governance is Critical to Info Security and Privacy - Michael Redmond - CSP #176 Video 28.05.2024 28:44
Data Governance is a key component in protecting the data from different points of view including information security confidentiality, integrity, and availability. There are several standards that have control requirements for Data Governance relating to PCI, HIPAA, and PII, data security and more. Two of the Internal Standards having Data Governance requirements are: GDPR, ISO/IEC 27001:2022 The...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.