G Mark Hardy & Ross Young
CISO Tradecraft®
You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level. © Copyright 2025, National Security Corporation. All Rights Reserved
Author
G Mark Hardy & Ross Young
Category
Podcast website
Latest episode
Jul 6, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
#91 - Hacker Summer Camp 15.08.2022 32:19
On this episode you can hear the tale of three conferences. Listen and learn about the history of BSides, Black Hat, and DEF CON. Learn what makes these conferences special and enjoy some of the untold history of each conference.
#90 - A CISO’s Guide to Pentesting 08.08.2022 16:00
A CISO’s Guide to Pentesting References https://en.wikipedia.org/wiki/Penetration_test https://partner-security.withgoogle.com/docs/pentest_guidelines#assessment-methodology https://owasp.org/www-project-web-security-testing-guide/latest/3-The_OWASP_Testing_Framework/1-Penetration_Testing_Methodologies https://www.pcisecuritystandards.org/documents/Penetration_Testing_Guidance_March_2015.pdf  ...
#89 - Connecting the Dots (with Sean Heritage) 01.08.2022 46:13
I've been a fan of Sean Heritage for years when I first discovered his blog, "Connecting the Dots." Today I have the privilege to listen to his thoughts on cybersecurity careers in both the military and the "real world," how to prioritize your life, what careers goals you should (and should NOT) aim for, and the importance of great leadership. Book reference: Connecting the Dots:...
#88 - Tackling 3 Really Hard Problems in Cyber (with Andy Ellis) 25.07.2022 47:11
This episode of CISO Tradecraft, Andy Ellis from Orca Security stops by to talk about three really hard problems that CISOs have struggled with for decades. How do we build a phishing program that works? How do we build a 3rd party risk management program that isn't a paper exercise? How do we actually get good at patch management? Stick around for some great answers such as: Human error is...
#87 - From Hunt Team to Hunter (with Bryce Kunz) 18.07.2022 43:47
On this episode of CISO Tradecraft, Bryce Kunz from Stage 2 Security stops by to discuss how offensive cyber operations are evolving. Come and learn how attackers are bypassing MFA and EDR solutions to target your cloud environment. You can also hear what Bryce recommends to beat the bear that is Ransomware. References: Link How Attackers Bypass MFA with Evilginx 2 Link St...
#86 - The CISO MindMap (with Rafeeq Rehman) 11.07.2022 45:24
This episode features Rafeeq Rehman . He discusses the need for a CISO Mindmap and 6 Focus Areas for 2022-2023: 1. Re-evaluate ransomware defenses, detection and response capabilities, perform a business impact analysis and identify critical processes, applications and data. 2. Reduce/consolidate security tools/technologies and vendors. More tools don’t necessarily reduce ri...
#85 - The Fab 5 Security Outcomes Study (with Helen Patton) 04.07.2022 44:20
On this episode of CISO Tradecraft, we feature Helen Patton . Helen shares many of her career experiences working across JP Morgan, The Ohio State University, and now Cisco. -Is technical acumen needed for CISOs? -Surviving organizational politics (34:45) Helen discusses The Fab 5 Security Outcomes study. Volume 1 Study - Link Volume 2 Study - Link
#84 - Gaining Trust (with Robin Dreeke) 27.06.2022 45:41
On this episode of CISO Tradecraft we feature Robin Dreeke from People Formula. Robin was the former head of the FBI Counterintelligence Behavioral Analysis Program and has an amazing background in learning how individuals think, build trust, and communicate. Robin highlights 4 Pillars of Communicating: Seek the thoughts and opinions of others Talk in terms of priorities, pain poi...
#83 - Cyber Defense Matrix Reloaded (with Sounil Yu) 20.06.2022 48:06
This episode is sponsored by Varonis . You can learn more on how to reduce your ransomware radius by performing a free ransomware readiness assessment Link On this episode, Sounil Yu continues his discussion about his new book (" Cyber Defense Matrix "). Listen to learn more about: Pre-Event Structural Awareness vs Post-Event Situational Awareness Environm...
#82 - Cyber Defense Matrix (with Sounil Yu) 13.06.2022 50:34
This episode is sponsored by Varonis . You can learn more on how to reduce your ransomware radius by performing a free ransomware readiness assessment Link This episode of CISO Tradecraft has Sounil Yu talk about his new book, " Cyber Defense Matrix : The Essential Guide to Navigating the Cybersecurity Landscape". Sounil reviews the Cyber Defense Matrix in depth. We discuss how th...
#81- Career Lessons from a CISO (with John Hellickson) 06.06.2022 41:27
On this episode of CISO Tradecraft, John Hellickson from Coalfire talks about his career as a CISO. Listen and learn about: The evolving role of the CISO How John got started as a CISO Whis is a Field CISO and how does it differ from a traditional CISO role Tips on getting your career to the next level by attending the right conferences and getting an executive coach How to get Business Alig...
#80 - Breaking Backbones (with Deb Radcliff) 30.05.2022 44:03
A respected journalist focusing on cybersecurity and our community of people for over 25 years, Deb Radcliff remains a trusted information source who checks and double-checks her sources before publication -- a refreshing change to the low signal - high noise world of social media. In this episode, we discuss where CISOs might turn for accurate information, how the industry has evolved in complexi...
#79 - Addressing the Top CEO Concerns 23.05.2022 38:32
On this Episode of CISO Tradecraft we talk about the Top 10 areas of concern for the C Suite about Ransomware. Note you can read the full ISC2 Study here ( Link ). Cybersecurity professionals should keep the following golden rules in mind when communicating with the C-suite about ransomware. Increase Communication and Reporting to Leadership Temper Overconfidence as Needed Tailor Your Messag...
#78 - Business Objectives & 5 CISO Archetypes (with Christian Hyatt) 16.05.2022 45:16
On this episode of CISO Tradecraft, Christian Hyatt from risk3sixty stops by to discuss the 3 major Business Objectives for CISOs: Risk Management Cost Reduction Revenue Generation He also discusses the five CISO Archetypes. The Executive The Engineer The GRC Guru The Technician The Builder References: The 5 CISO Archetypes Book Link Designing the CISO Role Link
#77 - Countering Corporate Espionage 09.05.2022 46:39
Chances are your organization has information that someone else wants. If it's another nation state, their methods may not be friendly or even legal. In this episode we address assessing risk, known "bad" actors, information targets, exfiltration, cyber security models, what the federal government is doing for contractors, and response strategies. Listen now so you...
#76 - The Demise of the Cybersecurity Workforce 02.05.2022 41:47
Our career has been growing like crazy with an estimated 3.5 million unfilled cybersecurity jobs within the next few years. More certs, more quals, more money, right? The sky’s the limit. But what if we’re wrong? AI, machine learning, security-by-design, outsourcing, and H-1B programs may put huge downward pressure on future job opportunities (and pay) i...
#75 - Avoiding Death By PowerPoint 25.04.2022 19:44
On this episode of CISO Tradecraft, we discuss how to avoid Death By PowerPoint by creating cyber awareness training that involves and engages listeners. Specifically we discuss: The EDGE method: Explain, Demonstrate, Guide, and Enable Escape Rooms Tabletop Exercises Polling During Presentations Short videos from online resources References: https://blog.scoutingmagazine.org/2017/05/05/livin...
#74 - Pass the Passwords 18.04.2022 42:42
On this episode of CISO Tradecraft, we focus on the Password Security and how it's evolving. Tune in to learn about: Why do we need passwords Ways consumers login and authenticate How bad actors attack passwords How long does it take to break passwords Different types of MFA The future of passwords with conditional access policies Infographic: References: https://danielmiessler....
#73 - Wonderful Winn Schwartau 11.04.2022 47:18
Winn Schwartau is a well-recognized icon in the cybersecurity community, and also a dear friend for over 25 years. Always one to stir the pot and offer radical ideas (many of which come true), we discuss Hacker Jeopardy, INFOWARCON, his books "Pearl Harbor Dot Com", "Time-Based Security", and his magnum opus "Analog Security." We speculate on the future of our industry with respect to...
#72 - Logging In with SIEMs (with Anton Chuvakin) 04.04.2022 48:28
On this episode of CISO Tradecraft, Anton Chuvakin talks about Logging, Security Information & Event Management (SIEM) tooling, and Cloud Security. Anton share’s fantastic points of view on: How moving to the cloud is like moving to a space station (13:44) How you may be one IAM mistake away from a breach (20:05) How a SIEM is a logging based approach, whereas EDRs require agents at endpoint...
#71 - Lessons Learned as a CISO (with Gary Hayslip) 28.03.2022 54:14
On this special episode of CISO Tradecraft, we have Gary Hayslip talk about his lessons learned being a CISO. He shares various tips and tricks he has used to work effectively as a CISO across multiple companies. Everything from fish tacos and beer to how to look at an opportunity when your boss has no clue about cyber frameworks. There's lots of great information to digest. ...
#70 - Partnership is Key 21.03.2022 16:01
On this episode of CISO Tradecraft you can learn how to build relationships of trust with other executives by demonstrating executive skill & cyber security expertise. You can learn what to say to each of the following executives to build common ground and meaningful work: CFO Legal Marketing Business Units CEO CIO HR Note Robin Dreeke mentions 5 keys to building goals.: Learn… a...
#69 - Aligning Security Initiatives with Business Objectives 14.03.2022 25:18
On this episode of CISO Tradecraft, we talk about how cyber can help the four business key objectives identified by InfoTech: 1. Profit generation: The revenue generated from a business capability with a product that is enabled with modern technologies. 2. Cost reduction: The cost reduction when performing business capabilities with a product that is enabled with modern technologies. 3...
#68 - Thought Provoking Discussions (with Richard Thieme) 07.03.2022 1:03:21
Today we speak with Richard Thieme, a man with a reputation for stretching your mind with his insights, who has spoken at 25 consecutive DEFCONs as well as keynoted BlackHat 1 and 2. In a far-ranging discussion, we cover the concept of what it's like to be a heretic (hint: it's one step beyond being a visionary), the thought that the singularity has already arr...
#67 - Knock, Knock? Who’s There and Whatcha Want? 28.02.2022 29:43
On this episode of CISO Tradecraft we are going to talk about various Access Control & Authentication technologies. Access Control Methodologies: Mandatory Access Control or (MAC) Discretionary Access Control or (DAC) Role Based Access Control or (RBAC) Privileged Access Management or (PAM) Rule Based Access Control Attribute Based Policy Control (ABAC) or Policy Based Access Control (PBAC) Authen...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.