G Mark Hardy & Ross Young
CISO Tradecraft®
You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level. © Copyright 2025, National Security Corporation. All Rights Reserved
Author
G Mark Hardy & Ross Young
Category
Podcast website
Latest episode
Jul 6, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
#66 - Working On The Supply Chain Gang 21.02.2022 20:40
On this episode of CISO Tradecraft , you can learn about supply chain vulnerabilities and the 6 important steps you can take to mitigate this attack within your organization: Centralize your software code repository Centralize your artifact repository Scan open source software for malware Scan software for vulnerabilities and vendor support Run a Web Application Firewall (WAF) Run a Runtime Applic...
#65 - Shall We Play A Game? 14.02.2022 43:31
Gamification is a superpower that CISOs can use to change the culture of an organization. On this episode of CISO Tradecraft we discuss how to use gamification concepts as a CISO. What’s in a Game? Objective Rules Challenge/Competition Randomness or unpredictability Designed for fun and sometimes learning What Makes a Game Fun? Challenge requires reasonable level of difficulty Fantasy c...
#64 - 3 Keys to Being a CISO (with Allan Alford) 07.02.2022 44:14
On this episode of CISO Tradecraft, we feature Allan Alford from The Cyber Ranch Podcast . Allan brings a wealth of knowledge as a CISO and shares the three things every CISO needs to bring to the table: Use a Cyber Maturity Model such as CMMI to identify the current situation and build a roadmap of where the organization is headed Quantify Known Risks through a Risk Register which get...
#63 - Flirting with Disaster 31.01.2022 26:22
As a cyber executive you should expect disaster and disruption. When these unfortunate events occur, you can protect the business by maintaining critical business functions, ensuring employees are able to access an alternate work facility, and providing vital records to perform business functions. The secret to accomplishing these objectives can be found in three important documents. T...
#62 - Promotion Through Politics 24.01.2022 31:06
On this episode, we talk about the four types of skills you need to demonstrate in your career to climb through the ranks: (Technical Skills, Management Skills, Leadership Skills, & Political Skills) We also highlight 6 crucial areas to improve your political skills Social Astuteness - You need to get your cues right. Socially astute managers are well-versed in social in...
#61 - Presentation Skills 17.01.2022 32:34
On this episode of CISO Tradecraft , we discuss how to give a great presentation. Starting with the Bottom Line Up Front (BLUF) Using pictures to Capture Attention Asking Thought Provoking Questions Succinct Points to tell a story Decision slides that show The problem The proposed solution Cost to implement solution Why alternatives are not as good Next Steps after decision is made We...
#60 - CISO Knowledge Domains Part 2 10.01.2022 17:44
One of the most common questions that we get asked on CISO Tradecraft is what do I need to learn to be a good CISO? After a lot of reflection, CISO Tradecraft put together a Top 10 List of CISO knowledge domains that we believe are the core skills which produce really good CISOs. This episode is a continuation from the previous episode and will go over the 6th -10th knowledge are...
#59 - CISO Knowledge Domains Part 1 03.01.2022 15:33
One of the most common questions that we get asked on CISO Tradecraft is what do I need to learn to be a good CISO? After a lot of reflection, CISO Tradecraft has put together a Top 10 List of CISO knowledge domains that we believe are the core skills which produce really good CISOs. This episode will go over just the first 5 knowledge areas with the remaining five on a future episode....
#58 - Active Directory is Active with Attacks 27.12.2021 26:52
After bad actors gain an initial foothold into an organization, they often use active directory attacks to gain administrative privileges. On this episode of CISO Tradecraft , we discuss Active Directory. You can learn what it is, how it works, common attacks used against it, and ways you can secure it. References: Stealthbits Active Directory Attacks Wikipedia Active Direc...
#57 - Brace for Audit 20.12.2021 15:12
You just got the news that the Cyber Organization is going to be audited. Do you know what an audit is, how best to prepare for it, and how to respond to audit findings? On this episode of CISO Tradecraft , we help you understand key auditing concepts such as: Audit Subject Audit Objective Vulnerability Threat Risk & Impact Audit Scope with Goals & Objectives Audit Plan Audit Response
#56 - Say Firewall One More Time 13.12.2021 31:28
Have you ever heard someone say our firewalls block this type of attack? In this episode, you can increase your understanding of firewalls so it won’t just be another buzzword. 6 Basic categories of firewalls that we discuss on the show include: Packet Filters focus on IP and port blocking Stateful Inspection Firewall looks at active connections and consider context N...
#55 - I have more Agents than the FBI 03.12.2021 16:32
On this episode of CISO Tradecraft you can learn all about Software Agents. Specifically we discuss: What does an Agent do, Why is an Agent helpful, and the 7 common types of Software Agents you would expect to find in large IT organizations. Also, if you stick to the end you can also learn about Secret Agents (ie Agentless). 7 Common Software Agents are: Endpoint Conf...
#54 - The Great Resignation 19.11.2021 36:26
The Great Resignation is upon us, and if some of your top talent hasn't given you their notice, it may be happening soon. Or not, depending on what you choose to do. With plenty of time to contemplate options, people are quitting jobs at a record pace. But wise leaders learn how to listen to their people's needs and desires, create a sense of purpose that motivates...
#53 - Fun and Games to Stop Bad Actors (with Dr. Neal Krawetz) 05.11.2021 44:17
In this episode, you can hear from Dr. Neal Krawetz , creator of Hacker Factor and FotoForensics. Neal's a long-time security practitioner who shares some fascinating insights in terms of how to identify potential bad actors early on (think reconnaissance interception), techniques for detecting bots and malicious entities, and ways to protect your team members from misattributed fake blog entries.
#52 - Welcome to the C-Level (with Nate Warfield) 29.10.2021 47:31
Special Thanks to our podcast Sponsor, Prevailion. Some of the best C-level executives start in the technical ranks. This episode features Nate Warfield , CTO of Prevailion , who differentiated himself by creating the CTI-League.com to assist healthcare companies with ransomware. We'll cover some of that organization, how Nate got his first C-level job, and some lessons...
#51 - New Kid in Town (with Rebecca Mossman) 18.10.2021 43:08
When you first start a cybersecurity job, or hire someone into a cybersecurity job, there is a window of opportunity to see things with a new perspective. In this episode, we’re privileged to share ideas with Rebecca Mossman, a successful cybersecurity leader who has led successfully a number of teams in her career. We’ll examine relationships, stakeholders, setting priorities, communi...
#50 - Border Gateway Protocol (BGP) 11.10.2021 31:25
A Border Gateway Protocol (BGP) misconfiguration is what took out Facebook on 4 October. Most IT folks don't understand how BGP works. This episode helps you gain a better understanding of the protocol that creates routing tables to move information from one end of the Internet to the other. We'll explain how Autonomous Systems (AS) share BGP route information, what should h...
#49 - Cyberlaw Musings (with Mark Rasch) 01.10.2021 43:35
This is a special treat. On this episode of CISO Tradecraft you can hear Mark D. Rasch, JD, discuss legal and security topics that he's encountered in his more than 30 years of experience in cybersecurity law. We look into ransomware, reportable breaches, the appropriateness (or lack thereof) of certain legal statues, and finish with some actionable advice for CISOs and security leader...
#48 - Effective Meetings 24.09.2021 33:24
We've all suffered through horrible meetings that felt like a total waste of time. As a security leader, you'll be convening your fair share of meetings with your staff. Don't be "that boss" who can't run an effective meeting. This episode shows ways you can ensure your meetings are both efficient and effective, result in actionable tasking, and keep people coming back for more b...
#47 - More Risky Business with FAIR 17.09.2021 42:53
In our 31 July 2021 Episode 42, Risky Business, we covered the basics of risk and risk assessment. This part 2 episode gets into the practical application of risk management using the FAIR model, or Factor Analysis of Information Risk. We explain key risk terminology and walk through examples of how to express risk using this model, as well as creating a meaningful way to explain to executives tha...
#46 - Crisis Leadership with G Mark Hardy‘s 9/11 Experience 10.09.2021 45:07
Have you ever faced a crisis? How well did you do? You should always want to improve your skills in case another happens. On the 20th anniversary of 9/11, G. Mark Hardy shares some of his experiences as the on-scene commander for the military first responders at the World Trade Center, and expands that into a set of skills and attributes that you can cultivate to become a more ef...
#45 - Protecting your Crown Jewels (with Roselle Safran) 03.09.2021 45:46
Traditional risk models focus on calculating loss frequency and magnitude, but don't go far enough in terms of modeling the most important assets in our organization, known as "crown jewels." This episode of CISO Tradecraft is a fascinating interview with the CEO and founder of a startup focusing on crown jewel analysis -- Roselle Safran . We'll look into how making this a part of your portfolio h...
#44 - Intro to Docker Containers and Kubernetes (K8s) 27.08.2021 31:19
Containers are a lightweight technology that allows applications to deploy to a number of different host Operating Systems without having to make any modifications at all to the code. As a result, we're been seeing a big increase in the use of Docker, Kubernetes, and other tools deployed by enterprises. In this episode, we'll cover the fundamentals of containers, Docker, orchestration...
#43 - Cyber Deception (with Kevin Fiscus) 20.08.2021 44:55
Join CISO Tradecraft for a fascinating discussion on how to build cyber traps for the bad guys that really work. By creating a deceptive environment that "booby-trap" your networks with fake services, enticing resources, and make-believe traffic, we can create a high-fidelity, low-noise intrusion sensor system -- no legitimate user would ever try these. Improve your SOC efficiency by a...
#42 - Third Party Risk Management (with Scott Fairbrother) 13.08.2021 52:29
Special Thanks to our podcast Sponsor, C yberGRX On today’s episode, we bring in Scott Fairbrother to help tackle key questions with Third Party Risk Management: How do you identify which vendors pose the highest risk to your business? How do you see which vendor’s security controls protect against threats? How do you validate their risk profiles by scanning, dark web monitoring or other tec...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.