CISO Series
Defense in Depth
Defense in Depth, hosted by David Spark, Steve Zalewski, Geoff Belknap, and Edward Contreras, promises clear talk on cybersecurity's most controversial and confusing debates. Once a week we choose one controversial and popular cybersecurity debate and use the InfoSec community's insights to lead our discussion.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Is Product Security Improving? 31.10.2019 26:06
All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-is-product-security-improving/ ) We've been at this cybersecurity thing for a long time. Are products improving their security? A recent study says they aren't. Check out this tweet and the ensuing discussion for the information on the study and the concerns people have about the history of...
Best Starting Security Framework 24.10.2019 26:46
All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-best-starting-security-framework/ ) If you were building a security program from scratch, which many of our listeners have done, which framework would be your starting point? Check out this post initiated by Sean Walls, vp, CISO of Visionworks, who asked, "If you were building a security pr...
Cyber Defense Matrix 17.10.2019 27:46
All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-cyber-defense-matrix/ ) A simple way to visualize your entire security program and all the tools that support it. Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark ( @dspark ), the creator of CISO Series and ...
User-Centric Security 10.10.2019 28:54
All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-user-centric-security/ ) How can software and our security programs better be architected to get users involved? Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark ( @dspark ), the creator of CISO Series and A...
Securing the New Internet 03.10.2019 32:22
All links and images from this episode can be found at CISO Series ( https://cisoseries.com/defense-in-depth-securing-the-new-internet/ ) If you could re-invent the entire Internet, starting all over again with security in mind, what would you do? Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark ( @dspark ), the crea...
Resiliency 26.09.2019 26:24
All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-resiliency/ ) How fortified is the business to withstand cyberattacks? Can it absorb the impact of the inevitable hits? Would understanding the business' level of resilience provide the appropriate guidance for our security program? Check out this post for the discussion that is the basis of...
Ransomware 19.09.2019 26:04
All images and links for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-ransomware/ ) Why is Ransomware so prevalent? Why are so many getting caught in its net? And what are some of the best tactics to stop its scourge? Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark ( @dspark ),...
Top CISO Communication Issues 12.09.2019 27:40
All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-top-ciso-communication-issues/ ) Understanding risk. Communicating with the board. Getting others to understand and care about security. What is the most vexing cybersecurity issue for a CISO? Check out this post by Kate Fazzini , cybersecurity reporter for CNBC, for the discussion that is t...
Cybersecurity Excuses 05.09.2019 24:40
All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-cybersecurity-excuses/ ) "I've got all the security I need." "I'm not a target for hackers." These are just a few of the many rationalizations companies make when they're in denial of cyberthreats. Why are these excuses still prevalent and how should a cyberprofessional respond? Check out th...
Employee Hacking 29.08.2019 25:40
All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-employee-hacking/ ) A cyber professional needs their staff, non-IT workers, and the board to take certain actions to achieve the goals of their security program. Should a CISO use the hacking mindset on their own people? Check out this post for the discussion that is the basis of our convers...
100% Security 22.08.2019 24:56
100% Security. A great idea that's impossible to achieve. Regardless, CEOs are still asking for it. How should security people respond and we'll discuss the philosophical implications of 100% security. Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark ( @dspark ), the creator of CISO Series and Allan Alford ( @All...
Proactive Security 15.08.2019 28:35
All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-proactive-security/ ) How proactive should we be about security? What's the value of threat intelligence vs. just having security programs in place with no knowledge of what attackers are trying to do? Check out this post for the discussion that is the basis of our conversation on this week'...
ATT&CK Matrix 08.08.2019 24:59
All images and links for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-attck-matrix/ ) Is the ATT&CK Matrix the best model to build resiliency in your security team? What is the best way to take advantage of the ATT&CK framework and how do you square away conflicting data coming in from your tools. What can you trust and not trust? And is the disparity of resul...
Hacker Culture 01.08.2019 25:29
All images and links for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-hacker-culture/ ) The hacker community needs a new PR campaign. Far too many people equate hacker with criminal. But hacker is a mindset of how one approaches security. What is that approach and why are CISOs so attracted to hiring hackers? Check out this post for the basis of our conversati...
Bad Best Practices 25.07.2019 23:33
All images and links for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-bad-best-practices/ ) All professionals like to glom onto "best practices." But in security, "best" practices may be bad out of the gate, become useless over time, or they're not necessarily appropriate for all situations. Stay tuned, we're about to expose some of the worst "best" practices....
Cyber Harassment 18.07.2019 23:43
All images and links are available on CISO Series ( https://cisoseries.com/defense-in-depth-cyber-harassment/ ) Whether a jilted lover or someone trying to wield their power over another, cyber harassment takes many forms and it doesn't stay in the digital world. It comes into our real world and gets very dangerous. What is it and how can it be thwarted? Check out this post and discussion for the...
CISO Series One Year Review 25.06.2019 28:09
Links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-ciso-series-one-year-review/) The CISO/Security Vendor Relationship Podcast is now more than a year old. On this episode, the hosts of both podcasts, reflect on the series and we respond to listeners critiques, raves, and opinions. Check out this post and this post for the basis of our convers...
Economics of Data 25.06.2019 27:42
All images and links for this episode available at CISO Series ( https://cisoseries.com/defense-in-depth-economics-of-data/) Do we understand the value of our data? Do our adversaries? And is the way we're protecting it making it too expensive for them to steal? Check out this post and discussion for the basis of our conversation on this week's episode co-hosted by me, David Spark ( @dspark ),...
Tool Consolidation 19.06.2019 23:52
All links and images can be found on CISO Series ( https://cisoseries.com/defense-in-depth-tool-consolidation/ ) While cybersecurity professionals always want more tools, more often than not they're dealing with too many tools delivering identical services. The redundancy is causing confusion and more importantly, cost. Why should you pay for it? How does it happen and how do InfoSec leaders conso...
Camry Security 12.06.2019 22:21
Links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-camry-security/ ) The Camry is not the fastest car, nor is it the sexiest. But, it is one of the most popular cars because it delivers the best value. When CISOs are looking for security products, are they also shopping for Camry's instead of "best of breed" Cadillacs? Check out this post and di...
Amplifying Your Security Posture 04.06.2019 26:52
All links and images can be found on CISO Series ( https://cisoseries.com/defense-in-depth-amplifying-your-security-posture/) In security, you never have enough of anything. But the scarecest resource are dedicated security people. When you're running lean, what are some creative ways and techniques to improve overall security? Check out this post and discussion for the basis of our conversation o...
ERP Security 30.05.2019 21:41
All images and links for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-erp-security/ ) For most organizations, their ERP solution holds its crown jewels. Should custom and complex applications that trade such vital customer and corporate data be secured any differently? Check out this post and discussion for the basis of our conversation on this week's episode...
Managing Obsolete (Yet Business Critical) Systems 22.05.2019 28:23
All links and images from this episode can be found at CISO Series ( https://cisoseries.com/defense-in-depth-managing-obsolete-yet-business-critical-systems/ ) Obsolete systems that are critical to your business. They're abandoned, unpatchable and unmanaged. We've all got them, and often upgrading is not an option. What do you do? Check out this post and discussion for the basis of our conversatio...
Cybersecurity Hiring 16.05.2019 25:30
All links and images for this episode can be found on CISO Series ( https://cisoseries.com/defense-in-depth-cybersecurity-hiring/ ) Everyone needs more security talent, but what kind of talent, how specialized, and what kind of pressure is hiring requirements putting on security professionals? Check out this post and discussion for the basis of our conversation on this week's episode co-hosted by...
How CISOs Discover New Solutions 09.05.2019 29:28
Find images and links for this episode on CISO Series ( https://cisoseries.com/defense-in-depth-how-cisos-discover-new-solutions/ ) Are security professionals so burned out by aggressive cybersecurity marketing that they're giving up on discovering new and innovative solutions? What are the best ways for cyber professionals to discover new solutions? Check out this post and discussion for the basi...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.