G Mark Hardy & Ross Young
CISO Tradecraft®
You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level. © Copyright 2025, National Security Corporation. All Rights Reserved
Author
G Mark Hardy & Ross Young
Category
Podcast website
Latest episode
Jul 6, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
#41 - Got any Threat Intelligence? 06.08.2021 41:04
Cyber Threat Intelligence is an important part of an effective CISO arsenal, but many security leaders don’t fully understand how to optimize it for their benefit. In this show, we examine why cyber threat intelligence is vital to fielding an effective defense, discuss the intelligence cycle, examine the four types of threat intelligence, and feature a special guest, Landon Winkelvoss of htt...
#40 - Risky Business 01.08.2021 44:06
In this episode, we take a deep dive into that four-letter word RISK. Risk is measurable uncertainty. As a component of Governance, Risk, and Compliance (GRC), risk management is an important part of a security leader's responsibility. Risk assessment is conducted for a number of reasons, and measuring risk is an important component of effectively overseeing our IT investments. We'll look at NIST...
#39 - Stressed Out? Find your Ikigai and 6 Invaluable Factors 23.07.2021 29:46
Being a CISO has been described as the "toughest job in the world." It comes with a lot of stress, which can lead to early burnout as well as a number of health and relationship problems. Well, we're going to tackle this elephant in the room and investigate some of the sources of stress and ways we can deal with it. 88% of CISOS report being "moderately or tremendously stressed"...
#38 - CMMC and Me 18.07.2021 31:22
This episode of CISO Tradecraft discusses CMMC. The Cybersecurity Maturity Model Certification (CMMC), is the US government response to the massive amounts of defense-related information compromised over the years from contractors and third parties. The program will be mandatory for all defense contractors by 2025, and has the potential to expand to the entire Federal government, affec...
#37 - Cyber Security Laws & Regulations 09.07.2021 42:59
On this episode of CISO Tradecraft , you will hear about the most prominent Cyber Security Laws and Regulations: The Health Insurance Portability and Accountability Act (HIPAA) advocates the security and privacy of personal health information Administrative Safeguards Physical Safeguards Technical Safeguards The Sarbanes-Oxley Act (SOX) is designed to provide transparency on anything that could ca...
#36 - IPv6 Your Competitive Advantage (with Joe Klein) 03.07.2021 44:15
This episode of CISO Tradecraft is all about IPv6, featuring Joe Klein . IPv6 is becoming the dominant protocol on the Internet, and CISOs should understand the implications of how their enterprise is potentially vulnerable to attacks that may come from that vector, as well as be aware of defenses that may originate from an effective IPv6 deployment. This broadcast will cover...
#35 - Setting Up an Application Security Program 25.06.2021 41:17
On this episode of CISO Tradecraft , you can learn how to build an Application Security program. Start with Key Questions for Security IT Operations Application Development/Engineering Groups Identify Key Activities Asset Discovery Asset Risk Prioritization Mapping Assets Against Compliance Requirements Setting up a Communications Plan Perform Application Security Testing Activities SAST DAS...
#34 - Metrics that Matter 18.06.2021 41:30
What is measured gets done. However before you measure you need to think about how best to measure. On this episode of CISO Tradecraft , we provide you new insights into optimizing metrics that matter. What is a Metric? Metrics drive outcomes. Before picking a metric consider the following: What data is required? What stories can it tell? What questions does it invite...
#33 - 10 Steps to Cyber Incident Response Playbooks 11.06.2021 43:59
On this episode of CISO Tradecraft , you can learn the 10 steps to Incident Response Planning: Establish a Cyber Incident Response Team Develop a 24/7 Contact list for Response Personnel Compile Key Documentation of Business-Critical Networks and Systems Identify Response Partners and Establish Mutual Assistance Agreements Develop Technical Response Procedures for Incident Handling that your team...
#32 - Brace for Incident (with Bryan Murphy) 04.06.2021 44:09
Special Thanks to our podcast Sponsor, CyberArk. Experienced CISOs know that it's not a matter of if, but when. Incidents happen, and there is an established response strategy nicknamed PICERL that works: (P)reparation (I)dentification (C)ontainment (E)radication (R)ecovery (L)essons Learned If we "shift left" with our incident planning, we can...
#31 - Executive Order on Improving the Nation’s Cybersecurity 28.05.2021 36:53
On this episode of CISO Tradecraft , you can learn about the new Executive Order on Improving the Nation's Cyber Security. The episode provides a brief background on three security incidents which have influenced the Biden administration: SolarWinds Microsoft Exchange Servers Colonial Pipeline Attack The episode then overviews the various sections of the new Executive Order: Policy Removing...
#30 - Cloud Drift (with Yoni Leitersdorf) 21.05.2021 42:56
This episode is sponsored by Indeni. On this episode of CISO Tradecraft , G Mark Hardy discusses with Yoni Leitersdorf (CEO and CISO of Indeni) the risks which can occur in a cloud environment after it has been provisioned. Essentially it's quite common for organizations to change their cloud environment from what was declared in a Terraform or Cloud Formation Script. These unapp...
#29 - Identity and Access Management is the New Perimeter 14.05.2021 44:58
Identity is the New Perimeter. On this episode of CISO Tradecraft you will increase your understanding of Identity and Access Management. Key topics include: Audit Trail Authentication Authorization Identity Compromise Least Privilege Microsegmentation Multi Factor Authentication (MFA) Privileged Access/Account Management (PAM) Role Based Access Control (RBAC) Single Sign On (SSO)
#28 - AI and ML and How to Tell When Vendors Are Full of It 08.05.2021 44:21
Have you ever heard a vendor has software features such as Artificial Intelligence (AI) or Machine Learning (ML)? What does that mean? On this episode we answer those questions so you know when vendors are full of it. Common reasons to use Artificial Intelligence Types of Artificial Intelligence What Machine Learning is How Machine Learning works How to select the right alg...
#27 - Roses, Buds, & Thorns 01.05.2021 5:06
Today, CISO Tradecraft hosts a 5 minute discussion to talk about reflection. The concept is Roses, Buds, and Thorns. It’s an exercise designed to identify opportunities to make positive change. Roses- What’s working Buds - What are new ideas Thorns- What do we need to stop If you would like to learn more please check out the article from MITRE We would love to hear your feedback here ....
#26 - Blockchain for CISOs 23.04.2021 44:43
On this episode CISO Tradecraft we dive into the world of blockchain. As a CISO you may be expected to explain to executives what the technology does and possibly how it works. Here's your briefing to make you successful. We'll cover: History of money and birth of bitcoin Why blockchain uniquely solves an age-old trust problem Potential business uses of block...
#25 - Slay the Dragon or Save the Princess? 16.04.2021 45:03
This episode CISO Tradecraft continues the Ransomware Discussion. Do you slay the dragon (avoid the ransom) or save the princess (recover your files)? Talking points include: Background on Ransomware What if we choose to pay a ransom? Is the Ransomware on the sanctions list? Negotiation/Payments Involving Law Enforcement Involving Legal Council Dealing with Cryptocurrencies
#24 - Everything you wanted to know about Ransomware 08.04.2021 45:50
Would you like to know more about Ransomware? On this episode of CISO Tradecraft , G Mark Hardy and Ross Young provide an in-depth discussion on Ransomware. Key discussions include: What is ransomware? Why does it work? Ransomware Types (Client-Side, Server-Side, & Hybrid) How each of these enter a target environment Ransomware Incidents The Economics of Ransomware How is Ransomware Ev...
#23 - NSA’s Top 10 Cybersecurity Mitigation Strategies 02.04.2021 43:57
If there's one place that knows how Advanced Persistent Threat (APT) actors work, it's the National Security Agency (NSA). On this episode of CISO Tradecraft G Mark Hardy and Ross Young discuss NSA's Top Ten Cybersecurity Mitigation Strategies and how to use them to secure your company. Since the mitigation strategies are ranked by effectiveness against known APT tactics, they can be used to...
#22 - Modern Software Development Practices 26.03.2021 45:37
Would you like to know the best practices in modern software development? On this episode G Mark Hardy and Ross Young overview the 12 Factor App and its best practices: Codebase: One codebase tracked in revision control with many deploys. Dependencies: Explicitly declare and isolate dependencies. Config: Store configurations in the environment. Backing Services: Treat backing services as att...
#21 - Your First 90 Days as a CISO (with Mark Egan) 19.03.2021 43:35
This special episode features Mark Egan (Former CIO of Symantec as well as VMWare). Mark discusses what he looks for during interviews with CISOs, what executives need to demonstrate during their first 90 days to be successful, and how he helps the next generation of cyber professionals at Merritt College. Three Questions to ask during any interview: What do you like best about this role? Wh...
#20 - Zero Trust 12.03.2021 45:15
Would you actually like to learn about what Zero Trust is without a bunch of marketing jargon? On this week's episode G Mark Hardy and Ross Young provide a thoughtful discussion on Zero Trust from NIST and Microsoft: Microsoft's Zero Trust Principles Verify Explicitly Use Least Privileged Access Assume Breach NIST 800-207 Seven Tenets of Zero Trust All data sources and computing services are...
#19 - Team Building 05.03.2021 44:54
Every leader needs to know how to lead and manage a team. On this episode G Mark Hardy and Ross Young share tradecraft on team building. Pitfalls to team building with becoming a hero Organizational Maturity Models (Levels 1-5) Tuckman Teaming Model (Forming, Storming, Norming, and Performing) Leadership Styles (Telling, Selling, Participating, & Delegating) Aligning your Team and Regaining...
#18 - Executive Presence 26.02.2021 48:19
Having the ability to inspire confidence is crucial to lead others and allows you the opportunity to gain access to executive roles. On this episode G Mark Hardy and Ross Young discuss executive presence: What is it Why you need it How to get it We will discuss Gerry Valentine's 7 Key Steps to building Your executive presence: Have a vision, and articulate it well Understand how others exper...
#17 - Global War on Email 19.02.2021 47:24
If you use email, this episode is for you. Attackers leverage email for ransomware, Business Email Compromise (BEC), account takeover, and other threats that can be reduced with effective technical controls (as well as user education.) These three tools all involve placing simple entries in your DNS records. To work effectively, the recipient also needs to be checking entries. Th...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.