Greg Schaffer

The Virtual CISO Moment

The Virtual CISO Moment dives into the stories of information security, information technology, and risk management pros; what drives them and what makes them successful while helping small and midsized business (SMB) security needs. No frills, no glamour, no transparent whiteboard text, no complex graphics, and no script - just honest discussion of SMB information security risk issues. Brought to you by vCISO Services, LLC, a leading provider of vCISO and information security risk management services. Visit https://vcisoservices.com to learn more. A Second Chance Publishing, LLC podcast.

Author

Greg Schaffer

Category

Technology

Podcast website

vcisopodcast.net

Latest episode

Jun 30, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Cyber Quick Strike - February 6, 2023 06.02.2023

https://www.reuters.com/legal/legalindustry/sec-reveals-2023-priorities-new-agenda-2023-01-31/ https://www.darkreading.com/mobile/hornetsecurity-combats-qr-code-phishing-with-launch-of-new-technology https://www.secureworld.io/industry-news/security-concerns-businesses-chatgpt https://thehackernews.com/2023/02/new-wave-of-ransomware-attacks.html https://www.techrepublic.com/article/the-importance-...

Infosec Wrap Up - February 3, 2023 03.02.2023

https://thehackernews.com/2023/02/new-high-severity-vulnerabilities.html https://nakedsecurity.sophos.com/2023/02/01/password-stealing-vulnerability-reported-in-keypass-bug-or-feature/ https://www.techrepublic.com/article/cybersecurity-bec-attack-mimics-vendors/ https://financialit.net/news/security/romance-scammers-break-over-60-hearts-and-wallets-every-week-warns-tsb-bank-reveals https://www.cnn...

Throwback Thursday - A Conversation with Gary Chan 02.02.2023

From October 4, 2022 - Gary Chan of Alfizo LLC helps businesses stay secure from hackers and insider threats, meet legal and regulatory compliance, and enable sales by meeting their customers' expectations for security. He is also a "security mentalist", and if you're like me and have never heard of this term, you need to check out this episode - it's fascinating! Gary's websites: • Creating memor...

S5E5 - A Conversation with Derek Morris 31.01.2023

Derek Morris is a virtual Chief Information Security Officer (vCISO) with almost 3 decades in IT, Information Security, Cybersecurity. He possesses numerous industry certifications including: CISSP, CISM, CISA, CDPSE, PCI-QSA, CCSFP, CCNA, and MCSA. Bachelor's Degree in Computer Information Systems from Bryant University with a minor in Applied Statistics. We discuss the virtual CISO space and wha...

Cyber Quick Strike - January 30, 2023 30.01.2023

Links: https://www.bbc.com/news/business-64452986 https://heimdalsecurity.com/blog/new-mimic-ransomware-uses-windows-search-engine-to-find-and-encrypt-files/ https://www.bankinfosecurity.com/blogs/targets-opportunity-how-ransomware-groups-find-victims-p-3365 https://www.securityweek.com/the-effect-of-cybersecurity-layoffs-on-cybersecurity-recruitment/ https://coruzant.com/security/three-essential-...

Infosec Wrap Up - January 27, 2023 27.01.2023

Article links:  https://www.theguardian.com/us-news/2023/jan/26/hive-ransomware-servers-seized-us https://www.msn.com/en-us/news/technology/microsoft-365-outages-affect-office-teams-and-more/ar-AA16IX6 https://www.securityweek.com/us-government-agencies-warn-of-malicious-use-of-remote-management-software/ https://www.darkreading.com/application-security/compromised-zendesk-employee-credential...

Throwback Thursday - A Conversation with Mark Burnette 26.01.2023

From September 28, 2022 -  Mark Burnette, Shareholder-In-Charge at LBMC Information Security, discusses his path from Senior IT Auditor to overseeing and directing LBMC’s Risk Services practice nationwide. He is very active in the information security community, including as co-founder and past president of the Middle Tennessee ISSA chapter (one of the largest in the world), and co-founder an...

S5E4 - A Conversation with BJ Withrow 25.01.2023

BJ Withrow, Manager, Major Accounts, East Coast at Tenable, is a self-proclaimed geek at heart and cybernerd by trade. When he is passionate about something, it comes out in everything he does, and he loves what he does. We cover a variety of topics, including cybersecurity for small and midsized businesses, exercising, and the importance of a servant's heart. Note a production error resulted in m...

Cyber Quick Strike - January 24, 2023 24.01.2023

Southwest upgrades, NIST CSF update, ransomware affects 1000 ships' connectivity,  ransomware threat in next 24 months, iOS 12 zero-day fix, SCOTUS infosec risk management fails, securing IoT (list), my appearance this morning on the KAJMasterclass, and a thanks to Cynomi for including me as a top vCISO influencer. https://www.ciodive.com/news/southwest-airlines-technology-data-upgrades-FAA/6...

Infosec Wrap Up - January 20, 2023 20.01.2023

T-Mobile breach (again), MailChimp breach (again), ransomware payments down, TikTok fined for cookie issue, Avast posts decryptor for BianLian, five trends for 2023, and leveraging LNK files.  https://www.wsj.com/articles/t-mobile-says-hackers-stole-data-on-about-37-million-customers-11674166048 https://techcrunch.com/2023/01/19/t-mobile-data-breach/ https://www.msn.com/en-gb/money/technology...

Throwback Thursday - A Conversation with Cy Sturdivant 19.01.2023

From September 27, 2022 - Cy Sturdivant, Director at Forvis (Cybersecurity Division), joins us to discuss his path from accounting and finance to cybersecurity and the audit field. We dive into controls, the Three Line of Defense model, and how audit as the third line helps organizations achieve and maintain a solid information security posture.

S5E3 - A Conversation with Brent Forrest 17.01.2023

Brent Forrest is a leader, architect, and strategic advisor of holistic cybersecurity. He has developed security programs across Oil & Gas, Financial, Insurance, and Construction industries including architecture of endpoint visibility/protection, managed detection and response (MDR), and security awareness as well as leading real-world cyberbreach response efforts. He is a graduate of Western...

Cyber Quick Strike - January 16, 2023 16.01.2023

Malware attack on CircleCI, FortiOS vuln exploited, RTU ransomware attack, Lifelock compromise, Cloudflare and .gov, how and why to improve security culture, and nine top-of-mind issues for CISOs in 2023. https://thehackernews.com/2023/01/malware-attack-on-circleci-engineers.html https://www.csoonline.com/article/3685670/attackers-deploy-sophisticated-linux-implant-on-fortinet-network-security-dev...

Infosec Wrap Up - January 13, 2023 13.01.2023

US air grounding due to one engineer's error, vuln in chromium browsers, Citrix vuln, Tech Republic bundle offer, 10 penetration testing decision factors, and why soft skills are necessary in infosec. https://www.dailymail.co.uk/news/article-11628753/FAA-flight-grounding-debacle-stranded-tens-thousands-hours-caused-engineer.html https://thehackernews.com/2023/01/experts-detail-chromium-browser.htm...

Throwback Thursday - A Conversation with Adam Bricker 12.01.2023

From September 20, 2022: Adam Bricker has led many career lives, from working on Tomahawk missiles to cofounding the Carolina Cyber Center, focused on hardening community resources and continuing education to address the nation's critical cybersecurity talent shortfall. He currently provides consulting services for businesses in high tech, IT-enabled and emerging markets as the founder of ePower L...

Cyber Quick Strike - January 9, 2023 09.01.2023

Experian security flaw, CISOs focus on three trends, email services encryption, importance of SaaS user permissions, $24B MATIC coin risk, and today's list: 10 CRUCIAL cybersecurity tips for small business. https://krebsonsecurity.com/2023/01/identity-thieves-bypassed-experian-security-to-view-credit-reports/ https://www.darkreading.com/microsoft/cisos-are-focused-on-these-3-trends-are-you- https:...

Infosec Wrap Up - January 6, 2023 06.01.2023

Flipper phish, Slack breach, LastPass last trust, Twitter account info for free, Iran DDoS attack, data privacy trends, and a question of whether or not to use a VPN firewall (feedback encouraged, email greg@gregschaffer.info). https://www.bleepingcomputer.com/news/security/ongoing-flipper-zero-phishing-attacks-target-infosec-community/ https://cybernews.com/security/slack-admits-security-breach/...

Throwback Thursday - A Conversation with Elvis Huff 05.01.2023

From September 13, 2022 - Elvis Huff is the Vice President - Director of Security/Information Security Officer for Wilson Bank and Trust. His path to bank ISO is not typical but is inspirational, with 12 years as a police officer prior to entering the world of banking. His reason for the transition involves faith and following a calling. He also produces an awesome security newsletter, Security St...

S5E1 - A Conversation with Dave Evangelista 03.01.2023

For our kickoff episode of Season Five, Dave Evangelista joins us. He has 20 years of experience with financial institutions and is currently the Vice President Information Technology for a midwestern credit union where he is responsible for the tactical direction, control, and ongoing analysis and planning for the credit union’s IT environment. Infrastructure, Operations, Critical Systems, Inform...

Cyber Quick Strike - January 2, 2023 02.01.2023

Twitter GDPR investigation, ransomware group clones victim's site, LockBit apologizes to children's hospital, ransomware ecosystem diversifying, IT Pros' cybersecurity fears, FinTech cybersecurity issues, and cybersecurity tools to keep you safe as a remote worker...sort of. https://gdprbuzz.com/news/twitter-faces-investigation-in-ireland-over-data-breach/ https://www.bleepingcomputer.com/news/sec...

The Virtual CISO Moment Wrap Up for Friday, December 30, 2022 30.12.2022

Ransomware not covered by cyber insurance, cyberattacks may be impossible to insure without some changes, whatever happened to UEBA, 100,000 students have their data exposed, six tips for hiring cybersecurity talent, and my predictions for 2023. https://www.jurist.org/news/2022/12/ohio-supreme-court-says-insurance-policy-does-not-cover-ransomware-attack-on-software/ https://www.techspot.com/news/9...

Throwback Thursday for December 29, 2022 - A Conversation with Donna Gallaher 29.12.2022

From September 6, 2022 - Donna Gallaher, President and CEO of New Oceans Enterprises, LLC, is a seasoned IT and information security pro providing virtual CISO and risk management services. She is a FAIR (Factor Analysis of Information Risk) evangelist and is passionate about growing the virtual CISO community, including serving on the Board of Directors for vCISO Catalyst, a Public Benefit Corpor...

The Virtual CISO Moment S4E64 - A Conversation with Michelle Drolet 28.12.2022

Michelle Drolet is a highly experienced information security expert who is well respected by clients, information security peers and analysts. Ms. Drolet is a sought-out speaker, panelist, and is a regular contributor to leading online publications such as Forbes Technology Council, Wired.com and IDG CSO Online. We discuss SMB security needs and challenges and how services such as a virtual CISO c...

VCM Quick Strike for Monday, December 26. 2022 26.12.2022

BetMGM breach, search engine ad attacks, ransomware with new encryption algorithm, new ransomware served by PrivateLoader, and an update on the LastPass breach, with some thoughts. https://www.bleepingcomputer.com/news/security/leading-sports-betting-firm-betmgm-discloses-data-breach/ https://www.infosecurity-magazine.com/news/fbi-cyber-search-engine-ads-attacks/ https://cybersecuritynews.com/vice...

The Virtual CISO Moment Wrap Up for Friday, December 23, 2022 23.12.2022

Okta breach, Gmail client side encryption, avoid clicking bad links not enough, and more predictions! https://www.bleepingcomputer.com/news/security/oktas-source-code-stolen-after-github-repositories-hacked/amp/ https://www.zdnet.com/article/google-brings-client-side-encryption-to-gmail-for-workspace/ https://www.ncsc.gov.uk/pdfs/blog-post/telling-users-to-avoid-clicking-bad-links-still-isnt-worki...

Listen to the The Virtual CISO Moment podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.