Chris Hughes

Resilient Cyber

Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries. As we watch the increased digitalization of our society, striving for a secure and resilient ecosystem is paramount.

Author

Chris Hughes

Category

Technology

Podcast website

www.buzzsprout.com

Latest episode

Jul 5, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

S4E14: Josh Reiter - U.S. Navy Workforce and Cyber Superiority 21.04.2023

Chris: Can you tell us a bit about your background and what the role of the Deputy Principal Cyber Advisor does? Nikki: When we talk about workforce challenges, I think about the types of skills that someone is looking for in a cyber program. What types of skills do you look for in hiring and what kinds of skills do we still need in the cyber profession?  Chris: We know you've been focused he...

S4E13: Chris Kulakowski - Threat Hunting & Detection Engineering 14.04.2023
S4E12: Kristin Saling - U.S. Army Workforce Modernization & Analytics 07.04.2023

Nikki - First - tell me a little bit about yourself and your background   Nikki - You have a ton of experience with the Army, can you talk a little bit about what you like most about working with the military and specifically in HR?  Chris - We hear a lot about digital transformation in the DoD, Cloud, Cyber, Zero Trust, and so on - but how critical do you think the workforce is to make all of the...

S4E11: John Speed Meyers - Data Science & Software Supply Chain Security 31.03.2023

Chris: I have been following your research for several years now, dating back to your role before Chainguard. As you have watched the conversation around Software Supply Chain Security unfold in the industry, do you feel like we're making positive headway? Chris: You have done a lot of research into software supply chain security, and of course SBOM's. One recent study you took a look at...

S4E10: Lily Zeleke - DoD Cloud & Software Modernization 27.03.2023

Chris: Before we dive into some technical topics and questions, we would love to hear a bit about your background and career Chris: - We've now seen the introduction of JWCC into the mix after quite a challenging road to get there. What major changes do you see JWCC playing in the DoD cloud landscape and cloud adoption journey? Nikki: - There's been a tremendous focus on software supply...

S4E9: Resilient Cyber Show w/ Day Johnson 24.03.2023

Nikki - With your experience in various cloud and Cybersecurity roles, what would you say the top 3 concerns are right now for cloud security?  Nikki -  I see you do a lot of work Cybersecurity and cloud education, do you feel like we have better tools and resources today than a few years ago? Or too many resources?  Chris - We know you have a Detection Engineering background. For folks not famili...

S4E8: Jim Dempsey - Cyber Policy & Regulation 10.03.2023

Chris - I have to start with the intersection of law and cybersecurity. We're seeing major strides in regulations, both federal and state (like NYFDS), to regulate and enforce cybersecurity policies and program-based guidance. What are some of the emerging trends we're seeing in cyber law?  Chris - As you know, we recently saw the new National Cyber Strategy, which makes a push for shift...

S4E7:Jeff Williams - DevSecOps and Application Security (AppSec) 04.03.2023

Nikki: I have to start with an article you wrote a couple of years ago, about how we explain and provide context around vulnerabilities. I love the analogy of a 'vulnerability recipe' and how we can step through an explanation of vulnerabilities. Can you talk a little bit about the process and what compelled you to explore this topic?  Nikki: I saw you spoke to Ron Ross recently, we had...

S4E6: Matt Cronin - Cyber Law & National Cyber Strategy 24.02.2023

Nikki: I saw you recently did a Cyber Jeopardy Panel at the American Bar Association about cybersecurity and cyber law - can you talk a little bit about the intersection of cybersecurity and law? Chris: Continuing on that thread a little more, and you and I have chatted about this, what are some of the dichotomies or challenges of Cybersecurity in a democratic society versus say an authoritative r...

S4E5: Robert Wood - The Soft Side of Cyber 12.02.2023

Chris: First off, why do you think soft skills are so often overlooked or undervalued in our field of cybersecurity? Chris: I'm curious your perspective on how to help people build soft skills, much like technical skills, some may have more of an aptitude for technical work or prefer not interacting with people as often. Any advice for folks who may be a bit more of an introvert and finding d...

S4E4: Derek Fisher - The AppSec Handbook 03.02.2023

Nikki: My first question is about your book, The Application Security Handbook - who do you think most benefits from this type of book and why do you think they need it? Nikki: What inspired you to write this? You have a ton of experience from being a security architect, to working in an IAM group, to application security - I would imagine all of that expertise allows you to see application securi...

S4E3: Dr. Nikki Robinson - Bridging the Gap with IT and Security 27.01.2023

- Can you tell us a bit about the book, what made you want to write it and how you settled on this topic? - Historically IT and Security have been at odds, often feeling like the other party is conflicting with their goals and responsibilities. Why do you think this is? - Do you think the push for DevSecOps and breaking down silos between Security and Operations (and Development) has helped at all...

S4E2: Karen Scarfone - Secure Software Development & NIST 15.01.2023

Nikki - What do you see as emerging trends around cybersecurity guidance and frameworks? With the newer NIST 800-53r5 and the SSDF, there is a TON of literature coming out from NIST. What's next?  Chris - I wanted to dig into SSDF a bit. Can you tell us a bit about being involved in that? How it came about after the Cyber EO and your experience writing it?  Chris - We know OMB is now requirin...

S4E1: Stephen Carter - The Vulnerability Management Landscape 09.01.2023

Nikki: To start us off, I'm curious about your opinion on the current state of vulnerability management guidance and documentation available for organizations. There are some references from NIST, but a lot of it centers around compliance.  Chris: How do you think things such as Cloud, DevSecOps and shift-left security have changed vulnerability management?  Nikki: Can you talk a little bit a...

S3E28: Chris Hetner - Cyber, the Board and Regulations 16.12.2022

Nikki - I wanted to start with the major explosion of ransomware and ransomware-as-a-service across all industries. This seems like a good starting point for why cybersecurity advisors belong in the boardroom. Do you think the sophistication and ease of purchase with ransomware should be part of the conversation to bring more cyber experts in?   Nikki - You made a post recently about the vast cybe...

S3E27: Varun Badhwar - OSS Governance and Vulnerability Management 28.11.2022

- Before we dive into the technical topics, you're a repeat Founder, including some acquisitions of firms you've founded. Can you tell us a bit about that Founders journey and what leads you to creating organizations? - Something you've been focused on a lot lately is Software Supply Chain Security. Why is this such a complicated topic, and has it always been, or do you feel it is i...

S3E25: Richard Stiennon - Cyber Industry Research and Analysis 12.11.2022

Nikki: With your latest book, the Security Yearbook for 2022 ,this is the third iteration of the series right? It started in 2020 and has only grown since then. Can you talk a little bit about why you started this annual compilation of research?  Nikki: For any other security practitioners or anyone in the field who's interested in writing a book or putting together a comprehensive manuscript...

S3E26: Mark Curphey - Challenges in SCA/SBOM and Modernizing OWASP 12.11.2022

- You recently wrote an article about the SBOM Frenzy being Pre-Mature. For those not familiar with SBOM's, what is an SBOM and what has led to the frenzy as you call it? - In your article you discuss challenges related to the build environments and hosts that can cause different outputs and SBOM's unless a build occurs on two identical machines. Can you explain why that is?  - What role...

S3E24: Chinmayi Sharma - Tragedy of the Digital Commons 27.10.2022

- First off, tell us a bit about your background, you were a developer prior to focusing on Law. Why the change and do you feel that technical background helps you in your legal and academic career? - Before we dive into the specifics of the paper and topics, what led you to focus on this issue for research and publication? - You penned an article about how modern digital infrastructure is built o...

S3E23: Richard Bird - Digital Identity & API Security 07.10.2022

- Looking at your background, you've held a lot of Identity-centric roles and positions in the industry. How do you think Identity and associated security is evolving with the continued adoption of Cloud? - Identity is obviously at the core of the conversation around Zero Trust, what do you think some of the fundamental things organizations get wrong when it comes IAM at-scale? - You recently...

S3E22: Steve Springett - Navigating the Digital Supply Chain 30.09.2022

Chris: Before we dive into too many specific topics, one thing I wanted to ask is, you've been working in/around the topic of SBOM and Software Supply Chain for sometime via NTIA, CycloneDX, SCVS etc. How did you have the foresight or what drove you to focus on this topic well before many others in the industry? Nikki: You mentioned recently about the SBOM Forum and their recommendation of th...

S3E21: Josh Bressers - Securing Open Source Software 23.09.2022

Chris: To start us off, why do you think OSS and the software supply chain are now beginning to get so much attention, despite being widely used for years now? Chris: When it comes to OSS, any thoughts on how we balance security while also not stifling the innovative creative environment that is the OSS ecosystem? Nikki: On one of your recent podcast episodes, you discussed how open source can be...

S3E19: Andres Vega & Andrew Clay Shafer - GRC in the Age of DevOps 20.09.2022

- What do you think some of the primary factors are that contributed to GRC not coming along initially with the DevOps movement? - Traditionally, what factors have plagued compliance when it comes to software delivery? - How do some of those factors change in the era of DevOps and Cloud-native? - Do you think regulation has a significant impact, and how can policy and regulation be improved? - How...

S3E20: Ken Myers - Federal ICAM & Zero Trust 20.09.2022

Chris: What do you think some of the fundamental changes of IAM are from on-prem to cloud? Chris: What are some of the key tradeoffs and considerations for using IDaaS offerings? Nikki: There are a lot of solutions out there that discuss zero trust as a product or a service that can be leveraged to 'bake in' zero trust into an environment. But I'm curious on your perspective - do yo...

S3E18: Jacques Chester - Vulnerability Scoring and Software Supply Chain 02.09.2022

Chris: For those not familiar with CVSS, what exactly is it, and why is vulnerability scoring important? Chris: What are some of the most notable critiques of CVSS? Nikki: I read your article 'A Closer look at CVSS Scores" and have had a lot of similar thoughts. The CVSS SIG is doing great work, and there are other scoring methods out there to help determine the real threat of vulnerabil...

Listen to the Resilient Cyber podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.