SecurityMetrics
Practical Cybersecurity with Jen Stone
Practical Cybersecurity , hosted by Jen Stone (MCIS, CISSP, CISA, QSA), is the bridge between complex security frameworks and real-world business implementation. Whether you are a "Jack of all trades" IT manager or a business leader with limited resources, this show provides the roadmap to a defensible security posture.
Author
SecurityMetrics
Category
Podcast website
Latest episode
Jul 7, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Making Your Trainings Less BORING | SecurityMetrics Podcast 43 25.01.2022 36:20
"If you want to engage your audience and get them involved in security rather than having to force them to do it, you need to give them something worth their time and attention." Making trainings for any audience can be hard, especially when it's mandatory. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) chats with Ian Murphy (Founder of Cyber Off, CISSP, FBCS, CITP) about h...
TOP 10 Breaches of 2021 | SecurityMetrics Podcast 42 08.12.2021 55:41
Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA), Matthew Heffelfinger (Director of SIEM Operations, GSTRT, CyRP (Pepperdine), GRCP, SSAP, ITIL4-F, GISF, PECB), and Forrest Barth (SOC Analyst, CISSP, CMNO, Security+) wrap up this season with the TOP 10 breaches of 2021! Join us for SEASON 3 of SecurityMetrics Podcast this January! A note from Jen: We built Practical Cybersecurity because we...
What Does Cybersecurity Cost? | SecurityMetrics Podcast 41 22.11.2021 46:42
Learn more at SecurityMetrics.com "That's one of the reasons why our audit team is so good, because we share the wing with forensics, and we're talking about what's happening out there. Our forensics consulting isn't theoretical. It isn't some monthly magazine saying 'look out for this... this might be happening,' this IS what's happening. This is the a...
Breaking Barriers in Cybersecurity | SecurityMetrics Podcast 40 10.11.2021 34:29
"One thing that I learned from the circle was how to come out of my comfort zone and tell my story to other people. When it comes to something technical, I can talk for hours, but apart from that it's very hard for me. So this was one take away for me, apart from all the learnings - both technical and non-technical - that really helped me a lot." Making your way in cybersecurity is...
Finding Your Path Into the Cybersecurity Workforce | SecurityMetrics Podcast 39 20.10.2021 29:31
Everybody has their own path to finding the job that's right for them. It's often easy to get discouraged when you're in the middle of the path to reach your desired goal. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) speaks with Luana Pascu (Cybersecurity Researcher, GSEC) about her personal journey, and how you can find the path in data security that's right for you...
Network Segmentation: Increasing Security and Focus on Compliance | SecurityMetrics Podcast 38 05.10.2021 32:55
"With network segmentation, we really are looking for isolation. We want to get that 'thing' and put it into a safety deposit box where you have secure access to it. Nobody else has physical or logical access to it. That's really what we are trying to do with segmentation." Network segmentation is often used to reduce the scope of a PCI DSS compliance assessment, but it is...
Zero Trust Tenets | SecurityMetrics Podcast 37 22.09.2021 28:56
"Zero Trust is essentially a security initiative saying that you are going to assume that attackers are present in any environment you're working in. The main goal of that is to remove implicit trust in the design and implementation of whatever you're doing." “Zero trust” is something we hear a lot about but in many cases it seems to be a buzzword used to sell us something. How...
How to Prepare for an Audit | SecurityMetrics Podcast 36 08.09.2021 34:43
Preparing for a third-party security assessment or compliance audit can be a daunting experience -- especially if it’s your first time. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) speaks with Brian Gross (VP, Product & Technology, FISERV) about how he prepared his organization to respond successfully to a PCI DSS assessment, followed by a HIPAA audit. Listen to learn: How a third-...
Legal Considerations for Privacy and Security | SecurityMetrics Podcast 35 25.08.2021 35:34
"Some security is better than no security. If you are a small business, and you don't have all the resources to invest in a huge cybersecurity program, that's ok! Start with the basics, such as strong passwords, the use of VPNs, and trainings on cyber threats like phishing and malware." Privacy and security considerations can be difficult to get your arms around; when laws and...
How to Manage 3rd Party Risk | SecurityMetrics Podcast 34 11.08.2021 32:11
"We all rely on service providers to keep our businesses afloat. I get asked all the time, 'How do I know that this service provider is going to be careful with my data?' Service providers can elevate our risk, while at the same time giving us really important services that we need. " When using service providers, managing your 3rd party risk can be a challenge. Tune in this w...
Keeping Kids Safe Online | SecurityMetrics Podcast 33 21.07.2021 33:04
"A lot of people don't realize, kids are smart! They know how to get around these controls that are in place. So the more informed you are as a caregiver, the more you can keep an eye on things that are going on with your kids and that they are getting the right information and aren't going to negative places." The internet is a vast and often dangerous place. With increasing t...
How to Prepare for a Risk Assessment | SecurityMetrics Podcast 32 07.07.2021 35:43
"Security is hard, even for professionals. There are a ton of things to know. As a defender, you have to be right 100% of the time. As an attacker, you kinda just have to get lucky once. If you go out there and educate people (in your company) about security, then they can become an ally for you." Join us this week as Jen Stone(MCIS | CISSP | CISA | QSA) and Matt Halbleib (CISSP | CISA |...
Ransomware - What You Need To Know | SecurityMetrics Podcast 31 23.06.2021 53:27
Subscribe to the Podcast! With so much ransomware stories in the news this year, one would think that ransomware is a new technique used by threat actors. In reality, ransomware has been around for almost a decade, and so have the basic principles on how to protect yourself from getting hit with it. Join Gary Glover (CISSP, CISA, QSA, PA-QSA) and Jen Stone (MCIS, CISSP, CISA, QSA) as they teach al...
Communicating with your IT Department | SecurityMetrics Podcast 30 09.06.2021 49:45
"It's the nature of our team's roles that there's always going to be trade-offs. It's hardly ever a simple decision between A and B. So you need to lean into that and get more comfortable with ambiguity." Having clear and open communication with your IT or security team is essential to maintaining a secure business. Although, if the correct steps are not taken, worki...
Teaching Data Security To Children | SecurityMetrics Podcast 29 26.05.2021 39:19
"I have a passion to keep people safe online, especially young ones. I don't expect kids to pick up this book and understand the concepts right away, but I want to empower the adults to teach. " Teaching data security and internet safety to the next generation can prove to be challenging. From the complex tools to the vast vocabulary, it's no simple thing to learn. Today, Host...
Choosing an MSSP | SecurityMetrics Podcast 28 12.05.2021 42:56
“What is managed security? It’s about trusting your business to someone else.” Whether you call it outsourcing, partnering, or hiring, choosing an MSSP is a decision that can seriously affect a business. SecurityMetrics Director of SIEM Operations and SecurityMetrics News Host, Matt “Heff” Heffelfinger, talked with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) about the ma...
The Myth of the Cybersecurity Workforce Shortage | SecurityMetrics Podcast 27 20.04.2021 33:29
Subscribe to the SecurityMetrics Podcast “Is there really a shortage of skills in cybersecurity? Or are we just looking at it the wrong way?” Director of Information Security and IT at BEEM Technologies, Naomi Buckwalter (CISSP, CISM) discovered hacking at Vanguard, where she joined a class and learned to hack from scratch. Her experiences as a software security architecture, security engineer, ca...
Gamify to Embed Security: Lessons from a Security Researcher | SecurityMetrics Podcast 26 07.04.2021 29:02
“What is our responsibility as leaders of security teams? It’s doing security right from the beginning; from the design. It has to be there.” Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) welcomes Vandana Verma: Security Architect IBM, Vice Chair of the Global Board of Directors at OWASP, leader at InfosecGirls, and founder of Infosec Kids. As a prolific speaker and thought leader...
Cybersecurity Innovation from Military to Enterprise | SecurityMetrics Podcast 25 24.03.2021 34:37
Dr. Oren Eytan joins Jen Stone (Principal Security Analyst, MCIS, CISSP, CISA, QSA) to discuss his experiences as a cybersecurity leader in both the military and civilian realms. After serving in the Israeli defense forces, two degrees in Electrical Engineering, and time at Motorola, Dr. Oren Eytan continues the fight against malware as the CEO of Odix. Today he helps protect businesses in all sec...
Payment Security: PCI DSS v4.0 Expectations | SecurityMetrics Podcast 24 09.03.2021 41:34
Subscribe to the SecurityMetrics Podcast There’s been a lot of chatter and anticipation about the release of PCI DSS v4.0. In this episode, SecurityMetrics VP of Assessments, Gary Glover (CISSP, CISA, QSA, PA-QSA), talks with Host Jen Stone (MCIS, CISSP, CISA, QSA) about what merchants can expect and how they should prepare right now. As part of the PCI DSS assessor community, Gary has worked with...
What is Social Engineering? Security Stories and Training Tips | SecurityMetrics Podcast 23 24.02.2021 47:08
People are naturally kind and helpful. Attackers know that, and in the case of social engineering–they rely on it. This week, Senior Information Security Architect at Lucid, Nathan Cooper (CISSP, Security+) talks with Host Jen Stone (MCIS, CISSP, CISA, QSA) about the tactics hackers use to attack businesses and how you can protect your company. Listen to learn: The psychological reasons social e...
How Executives and Security Professionals can Communicate Better | SecurityMetrics Podcast 22 10.02.2021 29:51
“How do you speak to executives about cybersecurity in a way that matters to them? It comes down to the company’s mission.” Ross Young, CISO of Caterpillar Financial Services Corporation, stops by SecurityMetrics Podcast to talk with Host and Principal Security Analyst, Jen Stone (MCIS, CISSP, CISA, QSA) about his mission to mentor the next generation of CISOs and create more understanding and har...
How to Get Cybersecurity Buy-In: SecurityMetrics CEO Brad Caldwell | SecurityMetrics Podcast 21 22.12.2020 41:39
“The single biggest contributor to data breaches is a lack of testing. You have to be testing, you have to be reviewing, you have to have pentests.” After experiencing a data breach as a small business owner 20 years ago, SecurityMetrics CEO Brad Caldwell (CISSP, CISA, QSA, PFI) set out to provide affordable data breach prevention and remediation to businesses of all sizes. Since then, SecurityMet...
3 Myths about PCI Compliance that Cost You Time | SecurityMetrics Podcast 20 09.12.2020 42:03
John Elliot has a knack for illuminating the relationship between security and compliance. With over ten years in information protection and compliance consulting, and as Director of Industry Standards at Mastercard, John helps explain the relevance of security and industry standards to customers and those in the wider payment ecosystem. Today he sits down with Host and Principal Security Analyst...
The Language of Security | SecurityMetrics Podcast Episode 19 25.11.2020 37:46
“If we think we’re fluent in security because we’re using the same words we’ve always used, we’re in danger.” With over 30 years in the FinTech industry, Dale Laszig has a long-range view of trends and technology that she has turned into a busy tech journalism career. Dale spoke with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) about the language of security: how the way...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.