SecurityMetrics

Practical Cybersecurity with Jen Stone

Practical Cybersecurity , hosted by Jen Stone (MCIS, CISSP, CISA, QSA), is the bridge between complex security frameworks and real-world business implementation. Whether you are a "Jack of all trades" IT manager or a business leader with limited resources, this show provides the roadmap to a defensible security posture. 

Author

SecurityMetrics

Category

Education

Podcast website

www.buzzsprout.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

SaaS Data Security and Supply Chain Risks | SecurityMetrics Podcast 68 09.05.2023

With the rise of Software-as-a-Service (SaaS), we are hearing more about related supply chain risks. Boris Sieklik, Senior Director of Information Security at MongoDB, sits down with Host and Principal Security Analyst Jen Stone  (MCIS, CISSP, CISA, QSA) to discuss: What SaaS means in the context of the cloud The risks third parties may introduce in terms of SaaS How leaders can prepare to handle...

Cybersecurity as an Operational Effort | SecurityMetrics Podcast 67 26.04.2023

Cybersecurity and risk management are often tossed to technical teams, but when these are driven by operations, the entire organization benefits. In today's episode, Jen Stone sits with Grant Elliott (CEO and co-founder of Ostendio, and Adjunct Professor at the Pratt Institute New York) to discuss: Communicating with upper-level management and set expectations on security success  Managing se...

Asset Management: Foundational to Cybersecurity | SecurityMetrics Podcast 66 12.04.2023

It is axiomatic in our industry that you can’t protect what you don’t know about, but assembling a comprehensive asset inventory can be much more difficult than it seems. Chris Kirsch, CEO of runZero, a cyber asset management company he co-founded with Metasploit creator HD Moore, sits down with Host and Principal Security Analyst Jen Stone  (MCIS, CISSP, CISA, QSA) to discuss: What asset manageme...

Identity Management: Why It Matters | SecurityMetrics Podcast 65 28.03.2023

Identity management is a critical aspect of any cybersecurity program. Creating the right roles and implementing a mature identity management lifecycle requires thoughtful collaboration between information technology and business operations. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) and Garret Grajek (CEH, CISSP, certified security engineer, product builder and CEO of YouAttest) sit...

CMMC: Protecting Critical Infrastructure | SecurityMetrics Podcast 64 15.03.2023

Critical infrastructure is under threat and has historically shown to be vulnerable. Protecting critical infrastructure is a wide-ranging effort that requires careful consideration. Tune in this week as Jen Stone  (MCIS, CISSP, CISA, QSA) and Katie Arrington (Former CISO for the Department of Defense and mother of the CMMC) discuss the current critical infrastructure landscape. Listen to learn: Wh...

HIPAA Basics: Where to Start with Practices and Training | SecurityMetrics Podcast 63 15.02.2023

HIPAA can be a daunting topic. Organizations often wonder where to start when implementing security or what kind of training is most effective. Listen this week as Jen Stone (MCIS, CISSP, CISA, QSA) sits down with Donna Grindle of Kardon and the “Help Me with HIPAA” Podcast to discuss: The work of 405(d) and how it can help your organization Exciting new training available through the PriSec Bootc...

Top Breaches of 2022 | SecurityMetrics Podcast 62 23.11.2022

"In 2021, we had tracked about 5.9M accounts were targeted through data breaches. It's expected that at the end of 2022, we will surpass that number." Tune in this week as Jen Stone and Heff give you the TOP data breaches of 2022. This list includes breaches caused by leaks, phishing, and poor cyber hygiene. Listen to learn: Most common breach types this year Tips to help your emplo...

Things You're Doing WRONG to Keep Your Data Safe | SecurityMetrics Podcast 61 10.11.2022

"A lot of people think they're doing all the right things to keep their data safe. However, there are things I see constantly that people are doing wrong, or not doing at all, to properly keep their data secure." Your personal data that exists online is vast and private. Should a hacker steal your data, you could lose emails, hard drives, bank accounts, or even your business. Tune i...

How Can ISOs Help Merchants With PCI Compliance? | SecurityMetrics Podcast 60 26.10.2022

Tune in this week as Jen Stone, Scott Robinson, and Robbi Watson discuss all things ISO. Listen to Learn: What is an ISO? How can ISOs help their merchants? Tips for an ISO / ISO Program Best Practices [Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assistin...

Privacy vs Security - Finding Balance in Compliance | SecurityMetrics Podcast 59 12.10.2022

"Privacy is not about things we want to hide. Hiding implies that the other side has a right to see what I'm trying to hide. Privacy means I can control what I share." Privacy rights are often unpinned from security, but they’re critical to recapture for our personal lives. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) speaks with Adrianus Warmenhoven  (Defensive Strategis...

Attack Surface Management | SecurityMetrics Podcast 58 21.09.2022

Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) and David Monnier (Chief Evangelist and Team Cymru Fellow at Team Cymru) discuss attack surface management. Listen to learn: What is an attack surface? Attack surface management VS vulnerability management VS endpoint security management. How can teams gain contextual awareness of their environments? Subscribe to the SecurityMetrics Podcast E...

PCI Standards: All You Need to Know | SecurityMetrics Podcast 07.09.2022

"The PCI Security Standards Council oversees a lot more standards than just PCI DSS. The council is very much involved with the payment lifecycle. We have standards to ensure the security of card data from start to finish." There are many standards out there to ensure the security of card data - each with a specific target to protect. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QS...

Cloud Security 101 | SecurityMetrics Podcast 56 24.08.2022

Subscribe to the SecurityMetrics Podcast Email! Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) and Chase Pettet (Chief Security Architect at Archer Integrated Risk Management) dive into cloud security 101. Listen to learn: What is driving the continued shift to the cloud? Does being in the cloud require organizations to think about their architecture differently? Is security radically dif...

Eliminating Friction Between Development & Security | SecurityMetrics Podcast 55 09.08.2022

"In order for us to meet our end objective of risk mitigation on software and applications, we have to get the developers on our side. If you do not collaborate with the developers, you're not going to be able to manage that risk" Tune in this week as Jen Stone and Harshil Parikh discuss how to eliminate friction between development and security. Listen to learn: How to collaborate...

Mobile Device Management - How to Securely Work Remote | SecurityMetrics Podcast 54 20.07.2022

"Not long ago, companies didn't allow employees to take their work devices home, or even out of the network. Companies relied on the network security for these devices. In the past few years, we have all been forced to shift and figure out - how do we still keep work secure?" Mobile device management is a heavy lift. Security teams recognize the risks posed by laptops, tablets, smar...

Cybersecurity Burnout - SOC Analyst Survey Findings | SecurityMetrics Podcast 53 22.06.2022

"I feel like many data security professionals feel like they're doing the right thing and making a difference, but there was a huge amount that said they were burning out. 65% of cybersecurity workers said they plan on leaving their jobs in the next 12 months." Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) speaks with Thomas Kinsella (COO and Co-Founder - Tines) about the...

PCI 4.0 SAQ (Self Assessment Questionnaire) - What's changed? | SecurityMetrics Podcast 52 08.06.2022

"The PCI Data Security Standard is a set of about 330 security controls that are designed to protect credit card information. For most small businesses, many of the requirements don't apply in their environment. The Self Assessment Questionnaire is a subset of the full PCI DSS standard designed to help small businesses validate their PCI compliance." PCI 4.0 is here, and many things...

How to Become a QSA | SecurityMetrics Podcast 51 25.05.2022

"Don't jump into becoming a QSA for a year and think 'I'm now going to go somewhere else and make a ton of money.' Spend some time really learning. That's the advantage to this job you can get so much experience so quickly and get exposure to so many aspects of cybersecurity." Breaking the barrier to the cybersecurity workforce can be difficult, especially if you...

The Future of Cybersecurity - Top 10 Cyber Trends | SecurityMetrics Podcast 50 11.05.2022

"The threat environment is becoming more aggressive, and the footprint that businesses need to protect is huge. Businesses need to reframe their expectations and reframe their focus." Reading the future is hard, especially in relation to cybersecurity. However, looking at current cyber trends helps us have a better idea of what is around the corner. Tune in this week as Jen Stone (MCIS,...

PCI 4.0 - What you need to know | SecurityMetrics Podcast 49 20.04.2022

"If we think back to 9 years ago when the previous version came out, the world was really different then. We now have loads of new criminals who have found new ways to steal card holder data. The way we do InfoSec has changed massively in 9 years, so we definitely needed a new standard." With PCI 4.0 just recently released, many are left with questions about the many changes in the stand...

P2PE Basics for Merchants (Point to Point Encryption) | SecurityMetrics Podcast 48 06.04.2022

"Simply, point to point encryption is encrypting your data at the beginning, and not decrypting it until it reaches its endpoint. This protects your data while it is being transferred." P2PE or “point-to-point encryption” can be the best way for merchants to take card present payments. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) speaks with Mark Miner (Director of P2PE/PIN As...

Home Cybersecurity 101 - Routers, Firewalls and More | SecurityMetrics Podcast 47 22.03.2022

Subscribe to the SecurityMetrics Podcast ! "Hackers don't solely go after Fortune 500 companies. Almost everyone I know has some story with their Facebook getting hacked, or their bank information getting stolen. The way to tackle that is cybersecurity for yourself." It's a common misconception that hackers only go after large companies or entities, when in reality they target...

Leadership in Cybersecurity | SecurityMetrics Podcast 46 08.03.2022

"How do I navigate this market, serve customers, and protect my brand reputation? At the executive level, that's the stuff they're thinking about. That trickles down to security objectives and initiatives. As a security leader, if you're in the head of your executive - what they want to do and why - then you can speak that language and drive better security." Maintaining s...

HHS 405(d) - What You Need To Know | SecurityMetrics Podcast 45 23.02.2022

HHS recently launched its new 405(d) website  to raise awareness, provide vetted cybersecurity practices, and move organizations towards consistency in mitigating the current most pertinent cybersecurity threats to the healthcare sector.  Donna Grindle of the “Help Me with HIPAA” Podcast, sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss: The work of...

How to Spot an Effective Security Practitioner | SecurityMetrics Podcast 44 09.02.2022

"In security, there is no 'that's not my job.' When it comes to defending the organization, security practitioners need to be able to put their egos aside, roll up their sleeves, and do what the team needs them to do to make sure the security posture of the organization continues to improve." Whether you're looking to hire a good security practitioner, or trying to be...

Listen to the Practical Cybersecurity with Jen Stone podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.