CISO Series

Defense in Depth

Defense in Depth, hosted by David Spark, Steve Zalewski, Geoff Belknap, and Edward Contreras, promises clear talk on cybersecurity's most controversial and confusing debates. Once a week we choose one controversial and popular cybersecurity debate and use the InfoSec community's insights to lead our discussion.

Author

CISO Series

Category

Technology

Podcast website

cisoseries.com

Latest episode

Jul 9, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Onboarding Cyber Professionals with No Experience 02.06.2022

All links and images for this episode can be found on CISO Series You want to bring on entry level personal, But green employees, who are not well versed in security, IT, or your data introduce risk once they have access to it. What are ways to bring these people on while also managing risk? Check out  this post  for the discussions that are the basis of our conversation on this week's episode co-...

Where's the Trust in Zero Trust? 26.05.2022

All links and images for this episode can be found on CISO Series Zero trust is a hollow buzzword. In any form of security, there exist critical points where we have to trust. What we need is a move away from implicit trust to explicit trust, or identity that can be verified. Check out  this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by me,  Dav...

Who Investigates Cyber Solutions? 19.05.2022

All links and images for this episode can be found on CISO Series Cyber professionals, who is responsible on your team for investigating new solutions? Check out  this post and this post  for the discussion that are the basis of our conversation on this week's episode co-hosted by me,  David Spark  ( @dspark ), the producer of  CISO Series , and  Steve Zalewski . Our guest is Nick Ryan , director...

Does the Cybersecurity Industry Suck? 12.05.2022

All links and images for this episode can be found on CISO Series In the cyber industry we pat each other on the back and give each other awards, all while the statistics for breaches appear to be worsening, Are we celebrating growing failure? Does the cyber industry suck? Check out  this post  for the discussions that are the basis of our conversation on this week's episode co-hosted by me,  Davi...

Are We Taking Zero Trust Too Far? 05.05.2022

All links and images for this episode can be found on CISO Series For some, the definition of zero trust has expanded from how we grant access to networks, applications, and data to how we trust individuals in the real world. Are we taking zero trust too far? Check out  this post  for the discussions that are the basis of our conversation on this week's episode co-hosted by me,  David Spark  ( @ds...

Is Shift Left Working? 28.04.2022

All links and images for this episode can be found on CISO Series Developers and security professionals have been heavily sold on the concept of "shift left" or deal with security issues early in development rather bolting it on at the end. It all made logical sense, but now we've been doing it for a few years and has shift-left actually reduced application security concerns? Check out  this post...

Technical vs. Compliance Professionals 21.04.2022

All links and images for this episode can be found on CISO Series Do we have a Monitgue/Capulet rivalry between technical and compliance professionals? Why is this happening, and what can be done to improve it? Does it need to be improved? Check out  this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by me,  David Spark  ( @dspark ), the producer o...

Why Do So Many Cybersecurity Products Suck? 14.04.2022

All links and images for this episode can be found on CISO Series Why do we end up with so many bad security products? Who is to blame and how can we fight back an ecosystem that may be fostering subpar products? Check out  this post  for the discussions that are the basis of our conversation on this week's episode co-hosted by me,  David Spark  ( @dspark ), the producer of  CISO Series , and  Geo...

Training for a Cyber Disaster 07.04.2022

All links and images for this episode can be found on CISO Series What are you doing to prepare for the next cyber disaster? You must train for it, because when it happens, and it will happen, everyone should know what they need to do. Check out  this post  for the discussions that are the basis of our conversation on this week's episode co-hosted by me,  David Spark  ( @dspark ), the producer of ...

Virtual Patching 31.03.2022

All links and images for this episode can be found on CISO Series What if you didn't spend all your time patching vulnerabilities but instead created a security policy that prevented known vulnerabilities from being exploited. How doable is this solution of virtual patching? Check out  this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by me,  Davi...

Start a Cybersecurity Department from Scratch 24.03.2022

All links and images for this episode can be found on CISO Series A 500+ person company doesn't have a security department. They need one and they need to convince the CEO they need one. How do you build a cybersecurity team and program from scratch? Check out  this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by me,  David Spark  ( @dspark ), the...

How to Think Like a Cybercrook 17.03.2022

All links and images for this episode can be found on CISO Series "If you want to catch a cybercrook, you need to think like one." But how do you actually go about thinking like a cybercriminal? What's the actual process? Check out this post  and this post for the discussions that are the basis of our conversation on this week's episode co-hosted by me,  David Spark  ( @dspark ), the producer of ...

Building a Data-First Security Program 10.03.2022

All links and images for this episode can be found on CISO Series Could you build a data-first security program? What would you do if you focused your security program on just the asset? Check out  this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by me,  David Spark  ( @dspark ), the producer of  CISO Series , and  Steve Zalewski . Our sponsored...

Offensive Security 03.03.2022

All links and images for this episode can be found on CISO Series Offensive security or "hacking back" has always been seen as either unethical or illegal. But now, we're seeing a resurgence in offensive security solutions. Are we redefining the term, or are companies now "hacking back?" Check out  this post  for the discussion that is the basis of our conversation on this week's episode co-hosted...

When Vendors Pounce on New CISOs 24.02.2022

All links and images for this episode can be found on CISO Series A security professional announces a new position as CISO. As a vendor you see this as good timing to try a cold outreach to sell your product. Why do so many vendors think this is a good tactic, when in reality it's exactly what you should not do? Check out  this post  for the discussion that is the basis of our conversation on this...

Building a Cybersecurity Culture 17.02.2022

All links and images for this episode can be found on CISO Series How do you begin building a cyber security culture for the whole company? And more importantly, how do you maintain that? Check out  this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by me,  David Spark  ( @dspark ), the producer of  CISO Series , and  Geoff Belknap  ( @geoffbelknap...

How to Pitch to a Security Analyst 10.02.2022

All links and images for this episode can be found on CISO Series You're a security vendor and you've got a short briefing with a security analyst from a research firm. What do you want to get across to them, and what do you want to hear back from them? Check out  this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by me,  David Spark  ( @dspark ),...

Is Your Data Safer in the Cloud? 03.02.2022

All links and images for this episode can be found on CISO Series Check out  this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by me,  David Spark  ( @dspark ), the producer of  CISO Series , and  Geoff Belknap  ( @geoffbelknap ), CISO,  LinkedIn . Our sponsored guest is Michael Johnson , CISO, Novi (the financial arm of Meta , formerly Facebook)...

What Should We Stop Doing in Cybersecurity? 27.01.2022

All links and images for this episode can be found on CISO Series Security professionals are drowning in activities. Not all of them can be valuable. What should security professionals stop doing be to get back some time? Check out  this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by me,  David Spark  ( @dspark ), the producer of  CISO Series , a...

DDoS Solutions 20.01.2022

How seamless are Distributed Denial of Service or DDoS solutions today? If you get a denial of service attack, how quickly can these solutions snap into action with no manual response by the user? Check out  this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by me,  David Spark  ( @dspark ), the producer of  CISO Series , and  Geoff Belknap  ( @geo...

Making Cybersecurity Faster and More Responsive 13.01.2022

All links and images for this episode can be found on CISO Series Knowing is only one-third the battle. Another third is responding. And the last third is responding quickly. It's not enough to just have the first two thirds. We need to be faster, but how? Check out  this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by me,  David Spark  ( @dspark...

Promises of Automation 06.01.2022

All links and images for this episode can be found on CISO Series Automation was supposed to make cybersecurity professionals' lives simpler. And it was supposed to solve the talent shortage. Has any of that actually happened? Check out  this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by me,  David Spark  ( @dspark ), the producer of  CISO Serie...

When Social Engineering Bypasses Our Cyber Tools 16.12.2021

All links and images for this episode can be found on CISO Series Check out  this post  for the discussion that is the basis of our conversation on this week's episode co-hosted by me,  David Spark  ( @dspark ), the producer of  CISO Series , and  Geoff Belknap  ( @geoffbelknap ), CISO,  LinkedIn . Our sponsored guest is  Josh Yavor  ( @schwascore ), CISO,  Tessian . Thanks to our podcast sponsor,...

How Can We Simplify Security? 09.12.2021

All links and images for this episode can be found on CISO Series Why is cybersecurity becoming so complex? What is one thing we can do, even if it's small, to head us off in the right direction of simplicity? Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me,  David Spark  ( @dspark ), the producer of  CISO Series , and  Steve Zale...

Convergence of Physical and Digital Security 02.12.2021

All links and images for this episode can be found on CISO Series Security convergence is the melding of all security functions from physical to digital and personal to business. The concept has been around for 17 years yet organizations are still very slow to adopt. A company's overall digital convergence appears to be happening at a faster rate than security convergence. Check out  this post  fo...

Listen to the Defense in Depth podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.