Cheri Hotman

The Art of Cybersecurity: Real-World Risk & Compliance Strategies

Cybersecurity is as much art as it is science or technology. It must be creatively designed, right-sized, implemented, and sustained—all within stealthy constraints: finite time, budget, resources. Meanwhile, customers demand this framework, that standard, and yet another security questionnaire. It’s a lot to juggle—balancing security that genuinely protects people and data with the theater that often slips into meaningless checkbox exercises. On this podcast, expect sharp, unfiltered conversations about the realities of cyber and what it truly takes to do it right—and make it actually matter.

Author

Cheri Hotman

Category

Technology

Podcast website

hotmangroup.com

Latest episode

Jun 12, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

AI Is Still Just a System: A Practical Approach to Governance 12.06.2026

In this episode, Cheri Hotman sits down with Diane Jones to explore the intersection of cybersecurity, engineering, and artificial intelligence. Drawing on her background in systems engineering and security, Diane shares her journey into AI governance and discusses how organizations can move beyond the hype and fear surrounding AI to focus on practical, actionable risk management. From NIST and IS...

The Art of Cybersecurity: Why Governance Is More Than Checklists 16.03.2026

In this episode of The Art of Cybersecurity , Cheri Hotman sits down with GRC leader Jerry Koshy for an honest, practitioner-to-practitioner conversation about what it really takes to build effective cybersecurity and risk programs. While compliance and risk management often get framed as rigid processes or box-checking exercises, Cheri and Jerry explore why the most impactful work in GRC is actua...

AI Without the Hype: People First, Governance Always 20.02.2026

AI is not the boogeyman. It is not a magic fix either. In this episode of The Art of Cybersecurity , Cheri Hotman sits down with Erica Shoemate (former FBI and U.S. intelligence community, now working across tech policy, trust and safety, and AI literacy) to talk about what most AI conversations miss: the human stakes. They dig into why “we passed the audit” is not the same as being secure, why in...

Continuous Improvement in Cyber: Findings Are the Point 02.01.2026

In this episode, Cheri Hotman sits down with long-time colleague and GRC leader Peter Spier for a candid, no-nonsense conversation about what actually keeps organizations secure and what quietly puts them at risk. Peter brings more than two decades of experience across PCI, audits, and enterprise risk to unpack a topic most teams avoid. Integrity in GRC. Together, they challenge the obsession with...

From CPA to Cyber Leader: Seeing the Whole Business 12.12.2025

In this episode, Cheri Hotman sits down with Joe Kodali, a fellow CPA turned cybersecurity and GRC leader, to have a blunt, practitioner-level conversation about what is actually broken in modern cybersecurity programs and why compliance theater is making organizations less secure, not more. They unpack the unique value CPAs bring to cybersecurity, not because of accounting, but because of how aud...

Inside CMMC: The Real Challenges, the Real Stakes, and the Real Work 11.12.2025

In this episode, Cheri Hotman sits down with CMMC expert and strategist Linda Rust for a direct, unscripted conversation about what CMMC really means for defense contractors, why so many organizations get it wrong, and how leaders can approach compliance with clarity instead of chaos. Linda brings more than 25 years of engineering and mission-critical technology leadership to the table. She breaks...

Beyond the Checklist CMMC with Integrity 24.09.2025

In this episode, Cheri Hotman unpacks the real story behind CMMC—and why it’s far more than a compliance checklist. Drawing on highlights from her recent Dallas talk, Cheri emphasizes that passing an audit is never the end goal. Instead, CMMC is about protecting sensitive government data, earning customer trust, and building integrity into every layer of your security program. Cheri breaks down th...

CMMC Demystified Scoping Compliance and Avoiding Costly Mistakes 29.08.2025

In this episode, Cheri Hotman and Paula Biggs break down the realities of CMMC compliance , with a special focus on scoping and avoiding common missteps. They explain how CMMC builds on existing NIST 800-171 requirements and why scoping—deciding which systems, people, and vendors fall under compliance—is the first and most critical step. Paula emphasizes that smaller companies can often save signi...

Beyond the Audit: Making Continuous Compliance Work 29.08.2025

Cheri Hotman and Tanya Wade cut through the checkbox mentality of audits to show why real compliance is about building programs that protect your people, data, and reputation year-round. From SOC 2 readiness to the pitfalls of over-relying on GRC tools, they share practical steps for prioritizing controls, assigning ownership, and reducing audit stress. If you’ve ever thought “we passed the audit—...

Episode 0: Why Cybersecurity Is as Much Art as Science 20.08.2025

In this kickoff episode of  The Art of Cybersecurity , host Cheri Hotman shares why this podcast exists and what listeners can expect. Cyber isn’t just science or technology — it’s art. It’s messy, constrained, people-driven, and ultimately about mitigating risk to protect people and data. Cheri cuts through the noise of “easy button” tools, audit-passing mentalities, and checkbox compliance to ta...

5 Tactics to Protect the Cloud Pt. 2 19.07.2022

Take these 5 tactics given by Cheri Hotman to help better protect the cloud.

5 Tactics to Protect the Cloud Pt. 1 18.07.2022

Take these 5 tactics given by Cheri Hotman to help better protect the cloud.

Cybersecurity is a Problem of People 05.05.2022

Cybersecurity is a Problem of People ➜ Hit the LIKE button ➜ SHARE the video with someone who might need it ➜ POST your questions in the comments for future video topics ➜ SUBSCRIBE for notifications of new episodes #cybersecurity #security #soc2 #vciso #compliance #risk #riskmanagement #grc #itrm #video #fintech #healthcare #healthcaretechnology #healthcaretech #software #saassecurity #ceo #ciso...

Pen Test to Remove Security Blindness 05.05.2022

Pen Test to Remove Security Blindness ➜ Hit the LIKE button ➜ SHARE the video with someone who might need it ➜ POST your questions in the comments for future video topics ➜ SUBSCRIBE for notifications of new episodes #cybersecurity #security #soc2 #vciso #compliance #risk #riskmanagement #grc #itrm #video #fintech #healthcare #healthcaretechnology #healthcaretech #software #saassecurity #ceo #ciso...

SaaS Tools Cover My Security, Right? 05.05.2022

SaaS Tools Cover My Security, Right? ➜ Hit the LIKE button ➜ SHARE the video with someone who might need it ➜ POST your questions in the comments for future video topics ➜ SUBSCRIBE for notifications of new episodes #cybersecurity #security #soc2 #vciso #compliance #risk #riskmanagement #grc #itrm #video #fintech #healthcare #healthcaretechnology #healthcaretech #software #saassecurity #ceo #ciso...

Even Policies Are Not Set-It-And-Forget-It 05.05.2022

Even Policies Are Not Set-It-And-Forget-It ➜ Hit the LIKE button ➜ SHARE the video with someone who might need it ➜ POST your questions in the comments for future video topics ➜ SUBSCRIBE for notifications of new episodes #cybersecurity #security #soc2 #vciso #compliance #risk #riskmanagement #grc #itrm #video #fintech #healthcare #healthcaretechnology #healthcaretech #software #saassecurity #ceo...

Don't Solve for the Wrong Problem 05.05.2022

Don't Solve for the Wrong Problem ➜ Hit the LIKE button ➜ SHARE the video with someone who might need it ➜ POST your questions in the comments for future video topics ➜ SUBSCRIBE for notifications of new episodes #cybersecurity #security #soc2 #vciso #compliance #risk #riskmanagement #grc #itrm #video #fintech #healthcare #healthcaretechnology #healthcaretech #software #saassecurity #ceo #ciso #ph...

Cybersecurity Does Not Equal Cool Tools 05.05.2022

Cybersecurity Does Not Equal Cool Tools ➜ Hit the LIKE button ➜ SHARE the video with someone who might need it ➜ POST your questions in the comments for future video topics ➜ SUBSCRIBE for notifications of new episodes #cybersecurity #security #soc2 #vciso #compliance #risk #riskmanagement #grc #itrm #video #fintech #healthcare #healthcaretechnology #healthcaretech #software #saassecurity #ceo #ci...

CEO's, Watch Your Assets 05.05.2022

CEO's, Watch Your Assets ➜ Hit the LIKE button ➜ SHARE the video with someone who might need it ➜ POST your questions in the comments for future video topics ➜ SUBSCRIBE for notifications of new episodes #cybersecurity #security #soc2 #vciso #compliance #risk #riskmanagement #grc #itrm #video #fintech #healthcare #healthcaretechnology #healthcaretech #software #saassecurity #ceo #ciso #phi #pii #p...

How to Respond to Security Questionnaires? 05.05.2022

How to Respond to Security Questionnaires? ➜ Hit the LIKE button ➜ SHARE the video with someone who might need it ➜ POST your questions in the comments for future video topics ➜ SUBSCRIBE for notifications of new episodes #cybersecurity #security #soc2 #vciso #compliance #risk #riskmanagement #grc #itrm #video #fintech #healthcare #healthcaretechnology #healthcaretech #software #saassecurity #ceo...

Why Can't I Just Download Policy? 05.05.2022

Why Can't I Just Download Policy? ➜ Hit the LIKE button ➜ SHARE the video with someone who might need it ➜ POST your questions in the comments for future video topics ➜ SUBSCRIBE for notifications of new episodes #cybersecurity #security #soc2 #vciso #compliance #risk #riskmanagement #grc #itrm #video #fintech #healthcare #healthcaretechnology #healthcaretech #software #saassecurity #ceo #ciso #ph...

Got Asked for It, But Don't Have SOC 2? 05.05.2022

Got Asked for It, But Don't Have SOC 2? ➜ Hit the LIKE button ➜ SHARE the video with someone who might need it ➜ POST your questions in the comments for future video topics ➜ SUBSCRIBE for notifications of new episodes #cybersecurity #security #soc2 #vciso #compliance #risk #riskmanagement #grc #itrm #video #fintech #healthcare #healthcaretechnology #healthcaretech #software #saassecurity #ceo #ci...

Minimal Security You Need for Cyber War 05.05.2022

Minimal Security You Need for Cyber War ➜ Hit the LIKE button ➜ SHARE the video with someone who might need it ➜ POST your questions in the comments for future video topics ➜ SUBSCRIBE for notifications of new episodes #cybersecurity #security #soc2 #vciso #compliance #risk #riskmanagement #grc #itrm #video #fintech #healthcare #healthcaretechnology #healthcaretech #software #saassecurity #ceo #ci...

5 Questions CEOs Should Ask on Cybersecurity 05.05.2022

5 Questions CEOs Should Ask on Cybersecurity ➜ Hit the LIKE button ➜ SHARE the video with someone who might need it ➜ POST your questions in the comments for future video topics ➜ SUBSCRIBE for notifications of new episodes #cybersecurity #security #soc2 #vciso #compliance #risk #riskmanagement #grc #itrm #video #fintech #healthcare #healthcaretechnology #healthcaretech #software #saassecurity #ce...

The Longer the Better Password 05.05.2022

The Longer the Better Password ➜ Hit the LIKE button ➜ SHARE the video with someone who might need it ➜ POST your questions in the comments for future video topics ➜ SUBSCRIBE for notifications of new episodes #cybersecurity #security #soc2 #vciso #compliance #risk #riskmanagement #grc #itrm #video #fintech #healthcare #healthcaretechnology #healthcaretech #software #saassecurity #ceo #ciso #phi #...

Listen to the The Art of Cybersecurity: Real-World Risk & Compliance Strategies podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.