Chris Hughes

Resilient Cyber

Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries. As we watch the increased digitalization of our society, striving for a secure and resilient ecosystem is paramount.

Author

Chris Hughes

Category

Technology

Podcast website

www.buzzsprout.com

Latest episode

Jul 5, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

S3E17: Anil Karmel - Compliance Innovation & RegOps 02.09.2022

Chris: So you're a proponent of a term called RegOps, can you explain what that is to us a bit and how it differs from traditional compliance? Nikki: I'm interested in your background from Solutions Architect, to CTO, to Co-founding and running companies. Do you have any advice for other architects or IT and security practitioners for building up leadership skills and transitioning to bu...

S3E16: Greg Thomas - Secure Service Mesh & Cloud-native Networking 01.09.2022

Nikki - In one of your recent posts you speak about how more organizations are looking to leverage service mesh in their own environments. Can you talk a little bit about why a team may be interested in moving to a more service mesh architecture?  Nikki: What do you think may impede or stop an organization from adopting updated networking practices and technologies, like service mesh, and how can...

S3E13: Jimmy Mesta - Kubernetes Security & Compliance 10.08.2022

Chris: For those not familiar with Kubernetes, can you tell us what it is and why there is so much buzz around it? Chris: Kubernetes, while it has many benefits also is a very complex technology, what are some of the key things organizations should keep in mind when using Kubernetes securely? Nikki: What kind of role do you see RBAC playing with Kubernetes? I don't hear a lot of talk around t...

S3E14: Jon Meadows - The Secure Software Factory 10.08.2022

 Nikki: In some ways I think "software supply chain security" has become almost a buzz word, or buzz phrase? But to me it's more of a concern for security programs at large, since so many products and services are being developed in-house at organizations. What are the top three concerns that CISO's or security leaders should know?  Chris: We're obviously seeing a lot of b...

S3E15: Aaron Rinehart - Chaos Engineering 10.08.2022
S3E12: Daniel Krivelevich of Cider Security - CI/CD Pipeline Security 22.07.2022

- For folks that are familiar, what is a CI/CD pipeline and why is it becoming such a hot topic in modern software delivery? - Do you think earlier on in the pursuit of DevOps/DevSecOps organizations overlooked the pipeline as an attack vector? - Any thoughts are notable incidents such as SolarWinds, do you think they brought more attention to the build environment? - What are you thoughts on emer...

S3E11: Larry Clinton w/ Internet Security Alliance: Cybersecurity as a Business Risk 11.07.2022

- Why do you think Cybersecurity has traditionally been seen as an IT issue? - With more and more of economic activity being tied to digital platforms, do you think organizations are realizing that cybersecurity is tied to business outcomes and value? - What do you think of recent activities by the SEC to require organizations to disclose cyber expertise among their board makeup? - How critical do...

S3E9: Rob Black - vCISO and Story Telling 07.07.2022

- For those unfamiliar with a vCISO, what is it and how is it different than a traditional CISO? - Do you feel like the SMB market is catching on to the necessity of a vCISO and how it is critical to enabling secure business outcomes? - How do organizations go about ensuring they get a qualified vCISO? Any things in particular to watch out for? - For those looking to get started as serving as a vC...

S3E10: Magno Logan - Container & Kubernetes Security 07.07.2022

- First off, for those not familiar with Containers and Kubernetes, what are they? - Why are organizations increasingly adopting these technologies over traditional forms of compute? - How does Cybersecurity change with Kubernetes and what are some things practitioners should be sure to keep an eye on? - When organizations are adopting Kubernetes they often are faced with options such as rolling t...

S3E8: Maril Vernon - Purple Teaming & Personal Branding 22.06.2022

Chris - Lets start off with discussing what is Purple Teaming exactly, and what is it not? Nikki - The industry can be somewhat siloed between job roles, and purple teaming really breaks down those barriers - do you see purple teaming being adopted more in the industry? Or do you think that too many industry experts hold too closely to their areas of expertise?  Chris - People often conflate Red T...

S3E5: Kelsei Young - Cybersecurity M&A & Doctoral Studies 16.06.2022
S3E6: Walter Haydock - Software Supply Chain & Vulnerability Management 16.06.2022

Nikki - You have some really awesome content on LinkedIn around Vulnerability management - one of my favorite posts you made recently was asking "Is vulnerability management dead". Can you explain a little bit about what you mean? I'm curious on your take, because there isn't a ton of modern guidance around vulnerability management   Nikki - One of the biggest challenges I thin...

S3E7: Robert Hurlbut - All Things Threat Modeling 16.06.2022

- For those not familiar with Threat Modeling, what is it? Also, to clear up potential confusion, what is it not? (e.g. Threat Hunting) - You were part of an effort to create the Threat Modeling Manifesto, can you tell us a bit about that project? - We recently saw NIST both define critical software as part of the Cyber EO and also list Threat Modeling as a key activity for critical software. What...

S3E2: Jacob Horne - Security vs. Compliance 23.05.2022

Nikki - You have a varied background between being a security engineer, consultant, manager, etc. What made you decide to focus more on the compliance aspects of cybersecurity? Chris - It is often said "Compliance doesn't equal Security". Why do you think this phrase has taken hold, do you think its accurate and how do we evolve beyond it?  Nikki -  Based on some of your posts about...

S3E3: Dan Lorenc - Software Supply Chain, Sigstore and OSS 23.05.2022

Chris: We're undoubtedly seeing a growing discussion around Software Supply Chain, with several notable events and also now evolving guidance/legislation such as the Cyber EO, NIST guidance etc. Any thoughts on why this is just now becoming such a focused concern? Nikki: When a lot of people discuss software supply chain security, it can quickly turn into a discussion about SBOM or Log4j and...

S3E4: Dr. Butler - Cybersecurity & Academia 23.05.2022

Chris - We know there's a massive Cyber workforce challenge, what role do you think academia plays there and how can it improve to close the gap? Nikki - Speaking of the young professionals in cybersecurity, what do you think are some of the in-demand skillsets and career paths available for individuals interested in pursuing a career in cybersecurity? Chris - There's often a debate betw...

S3E1: Bob Zukis - Cybersecurity in the Boardroom 23.05.2022

Chris: So let's start with how we've gotten here. With digital systems accounting for 60% of global GDP, how do we still not have requirements or adoption of cyber expertise on public board? Nikki: You mention in your article about the SEC mandating cyber leadership into board rooms - do you think that the type of experience expected on boards should be geared specifically to risk manage...

S2E24: Breaking Down the DoD Continuous ATO (cATO) Memo w/ Paul Puckett & Tyler Gesling 31.03.2022

A discussion with the Director of the Army Enterprise Cloud Management Agency (ECMA) - Paul Puckett and Cybersecurity Subject Matter Expert (SME) from DoD CIO-IE office, Tyler Gesling on the recent DoD cATO memo.

S2E23: Greg Touhill - Security/Boardroom Leadership & Zero Trust 30.03.2022

- We know you served as the First Federal U.S. CISO, can you tell us a bit about that experience? - In addition to your military and public sector background, you've held various industry roles as well, what are some of the major differences between the two environments you've experienced? - We know you've held various board advisor and even director roles. Do you feel that Cyber is...

S2E22: HackerOne - Bug Bounty, Vulnerability Disclosure and Ethics 25.03.2022

Nikki: I've spent a number of years studying vulnerability chaining and using low and medium vulnerabilities in combination to create very critical attacks. Do you see this as a common method for attacks in the wild? Chris: we're continuing to see the growth of bug bounty programs, such as HackerOne. How do you think these programs contrast (or compliment) companies internal pen test/red...

S2E21: Jerich Beason Emotional Intelligence, Cyber Leadership and SaaS Security 15.03.2022

You hold a variety of roles, from advisor, podcast host, CISO and have a great industry presence. How do you juggle it all, and what drives you to do so much? You recently spoke about emotional intelligence; do you feel it is overlooked in tech and cyber? You speak a lot about leadership in Cybersecurity. What are some of the characteristics you think are the most important for the modern cyber le...

S2E20: Tidelift - Open Source Software (OSS) & Software Supply Chain 08.03.2022

When you look at the state of the Open-Source Software (OSS) ecosystem, what do you think some of the biggest problems are? Why do you think we're now starting to see so much increased attention on the Software Supply Chain? When it comes to OSS maintainers and contributors, typically this is all done voluntarily and uncompensated in many cases. How is Tidelift looking to changing that paradi...

S2E19: Renee Wynn - Organizational Leadership, FISMA Reform and Soft Skills 01.03.2022

We know you’ve held several executive roles, we would love to hear your perspective regarding balancing business and organization leadership with the technology side Your recently testified before Congress regarding FISMA reform. Why do you feel this reform is so needed and what do you feel in particular would make the biggest impact?  What advice would you have for technology professionals who wa...

S2E18: John Guckian - EDR, XDR and Modern Endpoint Protection 23.02.2022

Nikki - What does EDR look like right now and where is it going? Nikki - What are the differences between typical A/V and EDR? Chris - What role do you see EDR playing in the push for Zero Trust?  Nikki - How do you integrate EDR into your environments and how do you feel about using EDR with SIEMs? Chris - Do you feel that the boon for working from home has impacted the EDR space? Nikki - Can you...

S2E17: Ron Ross (NIST) - DevSecOps, Resilience and Compliance Innovation 15.02.2022

Nikki - Can you tell us a little bit about what you're currently working on right now at NIST? Chris - Software Supply Chain Security has become a hot topic lately. We know NIST published 800-161 covering C-SCRM, C-SCRM is a complex topic. Where do you see the industry going forward in terms of maturing C-SCRM practices? Nikki - Speaking of maturing C-SCRM practices, do you feel that there is...

Listen to the Resilient Cyber podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.