CISO Series

Defense in Depth

Defense in Depth, hosted by David Spark, Steve Zalewski, Geoff Belknap, and Edward Contreras, promises clear talk on cybersecurity's most controversial and confusing debates. Once a week we choose one controversial and popular cybersecurity debate and use the InfoSec community's insights to lead our discussion.

Author

CISO Series

Category

Technology

Podcast website

cisoseries.com

Latest episode

Jul 9, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

What's an Entry Level Cybersecurity Job? 12.11.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-whats-an-entry-level-cybersecurity-job/ ) Naomi Buckwalter, director of information security at Energage analyzed one thousand random information security job posts on LinkedIn . The most notable trend she found was that 43% of the posts had CISSP and 5-year experience requirements for entry...

Securing Digital Transformations 29.10.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-securing-digital-transformations/ ) Digital transformation. It's definition is broad. Meaning securing it is also broad. But there are some principles that can be followed as companies undergo each step in a deeper dive to make more and more of their processes essentially computerized. Check...

Leaked Secrets in Code Repositories 22.10.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-leaked-secrets-in-code-repositories/ ) Secrets, such as passwords and credentials, are out in the open just sitting there in code repositories. Why do these secrets even exist in public? What's their danger? And how can they be found and removed? Check out  this post  for the basis for our c...

Measuring the Success of Your Security Program 15.10.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-measuring-the-success-of-your-security-program/ ) How does a CISO measure the performance of their security program? Sure, there are metrics, but what are you measuring against? Is it a framework or the quality of protection? How do you tell if your program is improving and growing? Check ou...

Privacy Is An Uphill Battle 08.10.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-privacy-is-an-uphill-battle/ ) Privacy is an uphill battle. The problem is those gathering the data aren't the ones tasked with protecting the privacy of those users for whom that data represents. Check out  this post  for the basis for our conversation on this week's episode which features...

Legal Protection for CISOs 01.10.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-legal-protection-for-cisos/ ) What's the legal responsibility of a CISO? New cases are placing the liability for certain aspects of security incidents squarely on the CISO. And attorney-client privilege has been overruled lately too. What does this mean for corporate and for CISO risk? Check...

XDR: Extended Detection and Response 24.09.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-xdr-extended-detection-and-response/ ) Is XDR changing the investigative landscape for security professionals? The "X" in XDR extends traditional endpoint detection and response or EDR to also include network and cloud sensors. Having this full breadth, XDR can contextualize alerts to tell a...

Calling Users Stupid 17.09.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-calling-users-stupid/ ) Many cybersecurity professionals use derogatory terms towards their users, like calling them "dumb" because they fell for a phish or some type of online scam. It can be detrimental, even behind their back, and it doesn't foster a stronger security culture. Check out ...

Is College Necessary for a Job in Cybersecurity? 10.09.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-is-college-necessary-for-a-job-in-cybersecurity/ ) Where is the best education for our cyber staff of the future? Where does college fit in or not fit in? Check out  this post  for the basis for our conversation on this week's episode which features me,  David Spark  ( @dspark ), producer of...

When Red Teams Break Down 03.09.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-when-red-teams-break-down/ ) What happens when red team engagements go sideways? The idea of real world testing of your defenses sounds great, but how do you close the loop and what happens if it's not closed? Check out  this post  for the basis for our conversation on this week's episode wh...

What Cyber Pro Are You Trying to Hire? 27.08.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-what-cyber-pro-are-you-trying-to-hire/ ) Do companies hiring cybersecurity talent even know what they want? More and more we see management jobs asking for engineering skills, and even CISO jobs with coding requirements. What's breaking down? Check out this post for the basis for our convers...

Junior Cyber People 20.08.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-junior-cyber-people/ ) There are so few jobs available for junior cybersecurity professionals. Are these cyber beginners not valued? Or are we as managers not creating the right roles for them to improve our own security? Check out this post for the basis for our conversation on this week's...

Trusting Security Vendor Claims 13.08.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-trusting-security-vendor-claims/ ) Do security vendors deliver on their claims and heck, are they even explaining what they do clearly so CISOs actually know what they're buying? Check out this post and the Valimail survey for the basis of our conversation on this week's episode which featur...

How Vendors Should Approach CISOs 06.08.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-how-vendors-should-approach-cisos/ ) "How do I approach a CISO?" It's the most common question I get from security vendors. In fact, I have another podcast dedicated to this very question. But now we're going to tackle it on this show. Check out this post for the basis of our conversation on...

Secure Access 30.07.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-secure-access/ ) What is the Holy Grail of secure access? There are many options, all of which are being strained by our new work from home model. Are we currently at the max? Check out this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by me...

InfoSec Fatigue 23.07.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-infosec-fatigue/ ) Have we reached peak InfoSec fatigue? Revolving CISOs and endless cyber recruitment OR the fact that we're spending more money to reduce even greater risk. Is it all leaving our grasp? Check out this post for the basis of our conversation on this week's episode which featu...

Securing a Cloud Migration 16.07.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-securing-a-cloud-migration/ ) You're migrating to the cloud. When did you develop your security plan? Before, during, or after? How aware are you and the board of the cloud's new security implications? Does your team even know how to apply security controls to the cloud? Check out this post...

API Security 09.07.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-api-security/ ) APIs are gateways in and out of our kingdom and thus they're also great access points for malicious hackers. How the heck do we secure them without overwhelming ourselves? Check out this post for the basis for our conversation on this week's episode which features me, David S...

Shared Threat Intelligence 02.07.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-shared-threat-intelligence/ ) We all know that shared intelligence has value, yet we're reticent to share our threat intelligence. What prevents us from doing it and what more could we know if shared threat intelligence was mandated? Check out this post for the basis for our conversation on...

Drudgery of Cybercrime 25.06.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-drudgery-of-cybercrime/ ) Why does the press persist on referring to all cyber breaches as sophisticated attacks? Is it to make the victim look less weak, or do they simply not know the tedium that's involved in cybercrime? Check out this post by Brian Krebs for the basis for our conversatio...

Security Budgets 18.06.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-security-budgets/ ) How do you calculate a security budget? Is it a percentage of the IT budget? Something else? And why does it grow so drastically after a breach? Thanks to this week's podcast sponsor, IronNet Cybersecurity. To combat sophisticated cyber threats, companies are increasingly...

Role of the BISO 11.06.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-role-of-the-biso/ ) What is a business information security officer or BISO? Do you need one? Is it just an extension of the CISO or is it simply taking on the business aspect of the CISO role? Check out this post for the basis for our conversation on this week's episode which features me, D...

Shared Accounts 04.06.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-shared-accounts/ ) As bad as all security professionals know, shared accounts are a fact in the business world. They still linger, and from an operational standpoint they're hard to secure and get accountability. Why are they still around and what can be done about them? Check out this post...

Bug Bounties 28.05.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-bug-bounties/ ) What is the successful formula for a bug bounty program? Should it be run internally, by a third party, or should you open it up to the public? Or, maybe a mixture of everything? Check out this post for the basis for our conversation on this week's episode which features me,...

Data Classification 21.05.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-data-classification/ ) The more data we horde, the less useful any of it becomes, and the more risk we carry. If we got rid of data, we could reduce risk. Check out this post for the basis for our conversation on this week's episode which features me, David Spark ( @dspark ), producer of CIS...

Listen to the Defense in Depth podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.