CISO Series

Defense in Depth

Defense in Depth, hosted by David Spark, Steve Zalewski, Geoff Belknap, and Edward Contreras, promises clear talk on cybersecurity's most controversial and confusing debates. Once a week we choose one controversial and popular cybersecurity debate and use the InfoSec community's insights to lead our discussion.

Author

CISO Series

Category

Technology

Podcast website

cisoseries.com

Latest episode

Jul 9, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Prevention vs. Detection and Containment 14.05.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-prevention-vs-detection-and-containment/ ) We agree that preventing a cyber attack is better than detection and containment. Then why is the overwhelming majority of us doing detection and containment? Check out this post for the basis for our conversation on this week's episode which featur...

Asset Valuation 07.05.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-asset-valuation/ ) What's the value of your assets? Do you even understand what they are to you or to a criminal looking to steal them? Do those assets become more valuable once you understand the damage they can cause? Check out this post for the basis for our conversation on this week's ep...

DevSecOps 30.04.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-devsecops/ ) We know that security plays a role in DevOps, but we've been having a hard time inserting ourselves in the conversation and in the process. How can we get the two sides of developers and security to better understand and appreciate each other? Check out this post  and this post...

Fix Security Problems with What You've Got 23.04.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-fix-security-problems-with-what-youve-got/ ) Stop buying security products. You probably have enough. You're just not using them to their full potential. Dig into what you've got and build your security program. Check out this post for the basis for our conversation on this week's episode wh...

Should Risk Lead GRC? 16.04.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-should-risk-lead-grc/ ) Defining risk for the business. Is that where a governance, risk, and compliance effort should begin? How does risk inform the other two, or does calculating risk take too long that you can't start with it? Check out this post  for the discussion that is the basis of...

Responsible Disclosure 09.04.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-responsible-disclosure/ ) Security researchers and hackers find vulnerabilities. What's their responsibility in disclosure? What about the vendors when they hear the vulnerabilities? And do journalists have to adhere to the same timelines? Check out this post  for the discussion that is the...

Internet of Things 02.04.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth:-internet-of-things/ ) When Internet of Things or IoT devices first came onto the market, security wasn't even a thought, let alone an afterthought. Now we're flooded with devices with no security and their openness and connectivity are being used to launch malicious attacks. What are method...

Is Governance the Most Important Part of GRC? 26.03.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-is-governance-the-most-important-part-of-grc ) Your policy should rarely change. But your ability to achieve that policy is found in procedures or governance that should inform, steer, and guide your team. Those procedures should change often and others should follow. Are they? Check out thi...

Who Should the CISO Report To? 19.03.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-who-should-the-ciso-report-to/ ) Who should the CISO report to? What factors determine that decision? And why is that single decision so critical to a company's overall security? Check out this post for the basis for our conversation on this week's episode which features me, special guest co...

Hybrid Cloud 12.03.2020

All links and images for this episode can be found on CISO Series (https://cisoseries.com/defense-in-depth-hybrid-cloud/) The consistency of your security program becomes a challenge once you introduce the cloud. Controls and visibility are not necessarily transferable. How do you maintain the control you want in a hybrid environment? Check out this post for the basis for our conversation on this...

CISO Tenure 05.03.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-ciso-tenure/ ) The CISO has the shortest tenure of any C-level role. Why so brief? Is it the pressure, the responsibility, the opportunities, or all of the above? Check out this LinkedIn discussion to read the basis of our conversation on this week's episode co-hosted by me,  David Spark  (...

Toxic Security Teams 27.02.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-toxic-security-teams/ ) There's an endless number of variables that contribute to creating a toxic security teams. How does it happen, and what are ways to manage and eradicate the toxicity? Check out this LinkedIn discussion to read the basis of our conversation on this week's episode co-ho...

Personality Tests in the Workplace 20.02.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-personality-tests-in-the-workplace/ ) As a cybersecurity leader, should you use personality tests for hiring and managing a team? Does it create diversity, understanding of communication styles, or does it just create more conflict? Check out this LinkedIn discussion to read the basis of our...

Lack of Diversity in Cybersecurity 13.02.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-lack-of-diversity-in-cybersecurity/ ) Cybersecurity teams are notoriously not diverse. At the same time we keep hearing and talking about the need for diversity. Is it critical? Can you be just as successful without it? Check out this Twitter feed for the discussion that is the basis of our...

When Are CISOs Responsible for Breaches? 06.02.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-when-are-cisos-responsible-for-breaches/ ) When is a CISO responsible for a breach or cyber incident? Should they be disciplined, fired, or let go with an attractive payout? Check out this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by me, ...

Post Breach Desperation and Salary Negotiations 30.01.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-post-breach-desperation-and-salary-negotiations/ ) A data breach usually spells financial and reputational disaster. But such an event can also be an opportunity for a security professional to capitalize. Check out this post  for the discussion that is the basis of our conversation on this w...

Presenting to the Board 23.01.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-presenting-to-the-board/ ) What metrics, reports, or strategies should a security professional utilize to communicate the value to the board? Or is the mode of "presenting to the board" a damaged approach? Check out this post  for the discussion that is the basis of our conversation on this...

The Iran Cybersecurity Threat 16.01.2020

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-the-iran-cybersecurity-threat/ ) The Iran conflict has threatened new retaliations and we don't know where they're going to come from. Cyber retaliation is a real possibility. Who's being threatened and how should we prepare? Check out this post  for the discussion that is the basis of our c...

Building a Fully Remote Security Team 09.01.2020

Links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-building-a-fully-remote-security-team/ ) Could you be successful with a fully virtual InfoSec team? Many say it can't be done, while some have actually done it and been successful. Check out this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by m...

Account Takeover 19.12.2019

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-account-takeover/ ) An account takeover traditionally follows a methodical path that takes considerable time before anything bad happens. Is it worth a company's time and effort to be monitoring a potential account takeover at the earliest stages? Check out this post  for the discussion that...

UX in Cybersecurity 12.12.2019

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-ux-in-cybersecurity/ ) Security products and programs may be functional and work correctly, but are they usable in the sense that it fits into the work patterns of our users? Check out this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by me,...

InfoSec Trends for 2020 05.12.2019

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-infosec-trends-for-2020/ ) We're coming to the end of the year and that means it's time to make our predictions for 2020. Mark this episode and check back in one year to see how we did. Check out this post  for the discussion that is the basis of our conversation on this week's episode co-ho...

Cybersecurity Readiness as Hiring Criteria 21.11.2019

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-cybersecurity-readiness-as-hiring-criteria/ ) What if every candidate interviewed was tested on their cybersecurity competency? How would that affect hiring and how would that affect your company's security? Check out this post  for the discussion that is the basis of our conversation on thi...

Cybersecurity and the Media 14.11.2019

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-cybersecurity-and-the-media/ ) Cybersecurity and the media. It rides the line between providing valuable information and feeding the FUD cycle. What's the media's role? Check out this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by me,  Davi...

The Cloud and Shared Security 07.11.2019

All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-the-cloud-and-shared-security/ ) When your business enters the cloud, you are transferring risk, but also adding new risk. How do you deal with sharing your security obligations with cloud vendors? Check out this LinkedIn post for the basis of this show's conversation on shared responsibilit...

Listen to the Defense in Depth podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.