M.G. Vance

CyberLex Leadership Audio Series

Exam mastery meets real-world judgment. If you’re studying CISA, CRISC, or CISM — or working in IT audit, risk, or cybersecurity — this podcast trains you to think like a leader. Not someday. Today. We simplify governance concepts, break down real scenarios, and teach the decision-making skills behind every exam domain. Beginner-friendly. Manager-approved. Boardroom-aligned. Grow your career, sharpen your instincts, and rise into the leader you already are. Listen. Learn. Lead with The Gold Standard.

Author

M.G. Vance

Category

Technology

Podcast website

www.amazon.com

Latest episode

Jan 4, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 28 – The Server That Was Always Up… Until the Day It Wasn’t | CISA Domain 4: Systems Availability & Capacity Management 04.01.2026

CISA Domain 4: Systems Availability & Capacity Management This episode is part of the CISA Domain 4 Deep-Dive Series, a structured curriculum that covers every subtopic in the 26% Information Systems Operations & Business Resilience domain. Each episode blends CISA exam reasoning with real-world audit leadership. In Episode 28, we explore a scenario where a business-critical authentication...

Episode 27 – The Spreadsheet That Became a System… Without Anyone Noticing | CISA Domain 4: Shadow IT & End-User Computing 02.01.2026

CISA Domain 4: Shadow IT & End-User Computing This episode is part of the CISA Domain 4 Deep-Dive Series, a structured curriculum that covers every subtopic in the 26% Information Systems Operations & Business Resilience domain. Each episode blends CISA exam reasoning with real-world audit leadership. In Episode 27, we explore how a simple spreadsheet evolved into a critical, undocumented,...

Episode 26 – The Interface That Sent Data… But Not the Truth | CISA Domain 4: System Interfaces 31.12.2025

CISA Domain 4: System Interfaces This episode is part of the CISA Domain 4 Deep-Dive Series, a structured curriculum that covers every subtopic in the 26% Information Systems Operations & Business Resilience domain. Each episode blends CISA exam reasoning with real-world audit leadership. In Episode 26, we examine a scenario where a data interface ran “successfully” — yet silently dropped hund...

Episode 25 – The Job That Completed Successfully… But Processed Nothing | CISA Domain 4: Job Scheduling & Production Automation 29.12.2025

CISA Domain 4: Job Scheduling & Production Automation This episode is part of the CISA Domain 4 Deep-Dive Series, a structured curriculum that covers every subtopic in the 26% Information Systems Operations & Business Resilience domain. Each episode blends CISA exam reasoning with real-world audit leadership. In this episode, we investigate a scenario where a critical job ran successfully...

Episode 24 – The Assets That Existed Everywhere… Except the Inventory | CISA Domain 4: IT Asset Management 27.12.2025

CISA Domain 4: IT Asset Management This episode is part of the CISA Domain 4 Deep-Dive Series, a structured curriculum that covers every subtopic in the 26% Information Systems Operations & Business Resilience domain. Each episode blends CISA exam reasoning with real-world audit leadership. In Episode 24, we examine a scenario where dozens of production servers existed — but none were recorded...

Episode 23 – The System Everybody Used… But No One Fully Understood | CISA Domain 4: IT Components Deep Dive 25.12.2025

CISA Domain 4: IT Components Deep Dive This episode is part of the CISA Domain 4 Deep-Dive Series, a structured curriculum designed to cover every subtopic in the 26% Information Systems Operations & Business Resilience domain. Each episode blends CISA exam reasoning with real-life audit judgment and operational leadership. In Episode 23, we explore a system that everyone depended on — yet no...

Episode 22 – The Security Test That Found Nothing… Because It Targeted the Wrong System | CISA Domain 5: Security Testing & Coverage Assurance 23.12.2025

CISA Domain 5: Security Testing & Coverage Assurance This episode is part of the CISA Audit Judgment Series — a structured, scenario-based learning path focused on Domains 4 and 5, the most heavily weighted sections of the CISA exam. In this episode, we examine a scenario where penetration testing was performed — but not against the actual production system. The test returned zero findings, no...

Episode 21 – The Disaster Recovery Test That Worked Only on Paper | CISA Domain 4: Business Continuity & DR Governance 21.12.2025

CISA Domain 4: Business Continuity & DR Governance This episode is part of the CISA Audit Judgment Series — a structured learning path focused on Domains 4 and 5, the heaviest-weighted areas of the CISA exam. In this episode, we analyze a Disaster Recovery test that was declared “successful” — even though no real failover occurred, no production data was restored, and no business validation to...

Episode 20 – The DLP Alerts Nobody Reviewed | CISA Domain 5: Data Loss Prevention & Monitoring Governance 19.12.2025

CISA Domain 5: Data Loss Prevention & Monitoring Governance This episode is part of the CISA Audit Judgment Series — a structured, scenario-based learning path focused on Domains 4 and 5, the heaviest-weighted areas of the CISA exam. In this episode, we explore a scenario where DLP is fully implemented and generating alerts — but no one is reviewing them. This exposes a critical truth in cyber...

Episode 19 – The Backup That Passed… But Never Restored | CISA Domain 4: Backup, Storage & Restoration Controls 17.12.2025

CISA Domain 4: Backup, Storage & Restoration Controls This episode is part of the CISA Audit Judgment Series — a structured, scenario-based learning path focused on Domains 4 and 5, the heaviest-weighted sections of the CISA exam. In this episode, we investigate a scenario where backups ran successfully for months — but none of them could be restored. This exposes one of the biggest weaknesses...

Episode 18 – The Encrypted Traffic That Wasn’t Authenticated | CISA Domain 5: Encryption & PKI Controls 15.12.2025

CISA Domain 5: Encryption & PKI Controls This episode is part of the CISA Audit Judgment Series — a structured, scenario-based learning path focused on Domains 4 and 5, the most heavily tested sections of the CISA exam. In this episode, we examine a scenario where TLS encryption is enabled — but certificate validation is disabled. The connection is encrypted, but authentication is nonexistent....

Episode 17 – The Incident That Closed Without a Root Cause | CISA Domain 4: Incident & Problem Management 14.12.2025

CISA Domain 4: Incident & Problem Management This episode is part of the CISA Audit Judgment Series — a structured learning path focused on Domains 4 and 5 , the heaviest-weighted sections of the CISA exam. In this episode, we examine a real scenario where a critical service outage was fixed quickly — but no root cause analysis (RCA) was performed. The incident was closed with a simple restart...

Episode 16 – The Endpoint That Stopped Reporting 132 Days Ago | CISA Domain 5: Endpoint Security & Monitoring Integrity 13.12.2025

CISA Domain 5: Endpoint Security & Monitoring Integrity This episode is part of the CISA Audit Judgment Series — a structured learning path covering Domains 4 and 5 , the most heavily tested areas of the CISA exam. In this episode, we review a scenario where an endpoint security agent appears installed and “healthy” according to dashboards — yet the device has not been reported in 132 days. Th...

Episode 15 – The Interface File That Arrived Empty | CISA Domain 4: System Interfaces & Data Integrity 12.12.2025

CISA Domain 4: System Interfaces & Data Integrity This episode is part of the CISA Audit Judgment Series — a scenario-based learning path focused on Domains 4 and 5 , the highest-weighted areas of the CISA exam. In this episode, we examine a scenario where an interface file arrives on time, processes without error, and passes all scheduler checks — yet contains zero records. No alerts were tri...

Episode 14 – The MFA Token That Still Worked After a Device Reset | CISA Domain 5: Authentication & Access Controls 11.12.2025

CISA Domain 5: Authentication & Access Controls This episode is part of the CISA Audit Judgment Series — a structured, scenario-based learning path focused on Domains 4 and 5 , the highest-weighted sections of the CISA exam. In this episode, we examine a scenario where a user resets their mobile device — but their old MFA token continues to authenticate across multiple systems. While the techn...

Episode 13 – The Database That Was Always Running Hot | CISA Domain 4: Availability & Capacity Management 10.12.2025

CISA Domain 4: Availability & Capacity Management This episode is part of the CISA Audit Judgment Series — a structured, scenario-based learning path focused on Domains 4 and 5 , the highest-weighted areas of the exam. In this episode, we explore a real audit scenario involving a production database consistently running near maximum capacity — with no alerts, no escalation, and no capacity pla...

Episode 12 – The Access That Still Worked After Termination | CISA Domain 5: Identity & Access Management 09.12.2025

CISA Domain 5: Identity & Access Management This episode is part of the CISA Audit Judgment Series — a structured learning path designed to teach CISA exam reasoning through real audit scenarios. We are currently covering Domain 4 and Domain 5 , the heaviest-weighted areas of the exam. Identity & Access Management questions are some of the trickiest in CISA Domain 5 because the exam focuse...

Episode 11 – The Batch Job That Looked Successful | CISA Domain 4: Job Scheduling & Processing Integrity 08.12.2025

CISA Domain 4: Job Scheduling & Processing Integrity This episode is part of the CISA Audit Judgment Series — a structured, scenario-based learning path designed to teach CISA exam judgment, real audit reasoning, and governance-first decision-making. We’re currently covering Domain 4 and Domain 5 , the heaviest-weighted domains in the CISA exam. Episodes alternate between the two domains to ma...

Bonus Episode – Access Management Judgment | CISA Domain 2: Identity & Access Controls 05.12.2025

This Access Management scenario was originally part of our Audit Judgment series, but we’ve moved it as a bonus episode for learners needing deeper clarity on CISA Domain 2. It covers: ✔ Identity and access principles ✔ How junior auditors interpret IAM gaps ✔ How audit leaders evaluate access failures ✔ What CISA actually tests in IAM-based questions ✔ Real-world evidence, governance, and risk re...

When Low Risks Combine into a High Risk | CRISC Risk Decision Lab Episode 10 03.12.2025

Most professionals evaluate risks one at a time. But real leaders — and every CRISC exam scenario — know the truth: Multiple low risks can combine into a high risk when they affect the same critical process. In this episode of the Risk Leadership Decision Lab, we unpack a real scenario where three “low” risks quietly stacked into a major exposure inside the customer identity-validation process. Yo...

The Control That Looked Fine on Paper | CRISC Risk Decision Lab Episode 9 03.12.2025

Organizations love controls on paper. But real risk leaders know the truth: A control not performed becomes an exposure — even if the policy looks perfect. In this episode of the Risk Leadership Decision Lab, we walk through a real scenario where privileged-access reviews were missed for months… without anyone noticing. You’ll learn how to detect quiet control failures, how to challenge assumption...

The Vendor Who Asked You to Trust Them | CRISC Risk Decision Lab Episode 8 03.12.2025

A vendor saying “tests are underway” does NOT mean a system is secure. And in real organizations — just like in CRISC, CISM, and CISA exams — leadership means approving evidence, not promises. In this episode of the Risk Leadership Decision Lab, we walk through a real-world scenario of a high-visibility project rushing toward go-live without completing security testing. You’ll learn how leaders ha...

The Dashboard That Hid the Truth | CRISC Risk Decision Lab Episode 7 03.12.2025

Dashboards don’t always tell the truth — they tell a story. And if you don’t know how that story was built, you’ll trust numbers that were never real to begin with. In this episode of the Risk Leadership Decision Lab, we break down a real scenario where a “perfect” availability dashboard hid months of silent failures. More importantly, we explore the leadership skill behind it: How to question met...

The Risk Everyone Owned and No One Claimed | CRISC Risk Decision Lab Episode 6 03.12.2025

Risk ownership is one of the most misunderstood concepts in cybersecurity and governance. Teams argue over who “touches the system,” who “wrote the rules,” or who “should” be accountable — but real risk ownership follows only one thing: Who controls the outcome. In this episode of the Risk Leadership Decision Lab, we unpack a real scenario where Operations, IT, and Data Governance all believed som...

The Access No One Should Have Combined | CISA Audit Judgment Foundation Episode 10 28.11.2025

Episode 10 — The Access No One Should Have Combined A user has both creation and approval access — a classic segregation-of-duties conflict. This episode teaches you how audit leaders evaluate SoD failures, privilege misuse, system control gaps, and governance exposure. You’ll learn: • segregation of duties • privilege creep • access governance • monitoring effectiveness • system control failures...

Listen to the CyberLex Leadership Audio Series podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.