CISO Series
Defense in Depth
Defense in Depth, hosted by David Spark, Steve Zalewski, Geoff Belknap, and Edward Contreras, promises clear talk on cybersecurity's most controversial and confusing debates. Once a week we choose one controversial and popular cybersecurity debate and use the InfoSec community's insights to lead our discussion.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
How Should We Trust Entry Level Employees? 08.06.2023 30:57
All links and images for this episode can be found on CISO Series . All experienced security professionals were at one time very green. Entry level status means risk to your organization. That's if you give them too much access. What can you trust an entry level security professional to do that won't impose unnecessary risk? And how can those green professionals build trust to allow them to do mor...
How Must Processes Change to Reduce Risk? 01.06.2023 28:47
All links and images for this episode can be found on CISO Series . What do we need to do to fix our processes to truly reduce risk and vulnerabilities? Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Steve Zalewski . Our sponsored guest is Amad Fida ( @brinqa ), CEO, Bri...
Reputational Damage from Breaches 25.05.2023 30:45
All links and images for this episode can be found on CISO Series . Security professionals talk a lot about the reputational damage from breaches. And it seems logical, but major companies still do get breached and their reputation seems spared. What's the reality of what breaches can do to a company's reputation? Check out this post for the discussion that is the basis of our conversation on thi...
Do RFPs Work? 18.05.2023 27:36
All links and images for this episode can be found on CISO Series . Do RFPs or request for proposals work as intended? It seems they're loaded with flaws yet for some organizations who must follow processes, they become necessary evils for both buyers and sellers. What can we do to improve the process? Check out this post for the discussion that is the basis of our conversation on this week's epis...
Successful Cloud Security 11.05.2023 31:13
All links and images for this episode can be found on CISO Series . What are the moves we should be making in cloud to improve our security? What constitutes a good cloud security posture? Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Andy Ellis , operating partner...
How Should Security Vendors Engage With CISOs? 04.05.2023 37:14
All links and images for this episode can be found on CISO Series . One CISO has had enough of the security vendor marketing emails and cold sales calls. He's blocking them all. But it's not a call to avoid all salespeople. He just doesn't have the time to be a target anymore. So how should vendors engage with such a CISO? And does CISO represent most CISOs today? Check out this post for the disc...
Gartner Created Product Categories 27.04.2023 34:32
All links and images for this episode can be found on CISO Series . Do we really need more categories of security products? Every new Gartner magic quadrant complicates the marketplace but at the same time helps us understand the other vectors we need to protect. Do new categories of security products help or hurt the industry? Check out this post for the discussion that is the basis of our conver...
How to Always Make a Business Case for Security 20.04.2023 31:07
All links and images for this episode can be found on CISO Series . How can security leaders and how do they go about matching business case to every security action you want to take? Is this the right way to sell security to the board? Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark ( @dspark ), the producer of CISO...
Do Breaches Happen Because the Tool Fails, or the Tool Was Poorly Configured? 13.04.2023 32:27
All links and images for this episode can be found on CISO Series. Security tools are supposed to do a job. Either they need to alert you, protect you, or remediate an issue. But they don't always work and that's why we have breaches. Who's at fault, the tool or the administrators who configured the tool? Check out this post for the discussion that is the basis of our conversation on this week's...
What We Love About Working in Cybersecurity 06.04.2023 28:53
All links and images for this episode can be found on CISO Series . We talk a lot on this show about what makes cybersecurity such a hard job, yet there are so many people who are in it and love it. What draws people to this profession and why do they love it so much? Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark...
Security That Accounts for Human Fallibility 30.03.2023 31:55
All links and images for this episode can be found on CISO Series . We expect our users to be perfect security responders even when the adversaries are doing everything in their power to trick them. These scams are designed to make humans respond to them. Why aren't we building our security programs to account for this exact behavior that is simply not going to go away? Check out this post for the...
Why You Should Be Your Company's Next CISO 23.03.2023 27:55
All links and images for this episode can be found on CISO Series . How do you make the argument that your company needs a CISO, and that YOU should be that leader? What do you need to demonstrate to prove you can be that person? Check out this post and this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark ( @dspark ), the produce...
How to Become a CISO 16.03.2023 30:46
All links and images for this episode can be found on CISO Series. How do you become a CISO? It doesn't follow a linear pattern as many other professions. There are many different paths and there are many different entry points. Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series ,...
Can You Build a Security Program on Open Source? 09.03.2023 25:10
All links and images for this episode can be found on CISO Series . What would it take to build your entire security program on open source software, tools, and intelligence? Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, Lin...
Third Party Risk vs. Third Party Trust 02.03.2023 28:40
All links and images for this episode can be found on CISO Series . Businesses grow based on trust, but they have to operate in a world of risk. Even cybersecurity operates this way, but when it comes to third party analysis, what if we leaned on trust more than trying to calculate risk? Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted b...
How Can We Improve the Cyber Sales Cycle? 23.02.2023 26:11
All links and images for this episode can be found on CISO Series The cybersecurity sales process is so terribly inefficient. And everyone, the targets and cybersecurity leaders, are losing valuable time because of that inefficiency. Where can we start making improvements? Check out this post for the discussion that's the basis for this podcast episode. This week's Defense in Depth is hosted by me...
What Leads a Security Program: Risk or Maturity? 16.02.2023 32:58
All links and images for this episode can be found on CISO Series . When you think about building a plan (and budget!) for your security program, do you lead with risk, maturity, or something else? Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Steve Zalewski . Our guest...
Limitations of Security Frameworks 09.02.2023 28:14
All links and images for this episode can be found on CISO Series Why do strongly supported security frameworks have such severe limitations when building a security program? Check out this post for the discussions that is the basis of our conversation on this week's episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, Li...
Why Is There a Cybersecurity Skills Gap? 02.02.2023 32:18
All links and images for this episode can be found on CISO Series . Why is there a cybersecurity skills gap? Practically everyone is looking to hire, and there are ton of people getting training and trying to get into the industry, but we still have this problem. Why? Check out this post for the discussions that is the basis of our conversation on this week's episode co-hosted by me, David Spar...
What Can the Cyber Haves Do for the Cyber Have Nots? 26.01.2023 32:18
All links and images for this episode can be found on CISO Series . Given that your company's security is dependent on the security of your partners and others, what can we do to get more organizations above the security poverty line? Check out this post for the discussions that is the basis of our conversation on this week's episode co-hosted by me, David Spark ( @dspark ), the producer of C...
Securing Unmanaged Assets 19.01.2023 30:33
All links and images for this episode can be found on CISO Series . "When the asset discovery market launched, every single company that offered a solution used the line, "You can't protect what you don't know." Everyone agreed with that. Problem is, "what you don't know" has grown… a lot." Check out this post for the discussion that is the basis of our conversation on this week's episode co-hoste...
Ambulance Chasing Security Vendors 12.01.2023 32:44
All links and images for this episode can be found on CISO Series A good high profile security threat seems like a good time to alert potential customers about how your product could help or even prevent a breach. Seems like a solid sales tactic for any industry that is not cybersecurity. Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted...
Do CISOs Have More Stress than Other C-Suite Jobs 05.01.2023 30:38
All links and images for this episode can be found on CISO Series Why do CISOs seem more stressed out than other C-level executives? Check out this post for the discussions that are the basis of our conversation on this week's episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, LinkedIn . We welcome our guest Jared Mende...
How Should We Discuss Cyber With the C-Suite? 15.12.2022 28:40
All links and images for this episode can be found on CISO Series How detailed do we get in our conversation with business leaders? Do we dumb it down? Or is that a recipe for trouble? Check out t h is post for the discussions that are the basis of our conversation on this week's episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelkna...
Can You Be a vCISO If You've Never Been a CISO? 08.12.2022 28:40
All links and images for this episode can be found on CISO Series Why are there so many vCISOs who have never been a CISO? Isn't it difficult to advise on a role you've never done? Do organizations feel comfortable hiring an inexperienced vCISO as their CISO? Check out this post for the discussions that are the basis of our conversation on this week's episode co-hosted by me, David Spark ( @ds...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.