Greg Schaffer

The Virtual CISO Moment

The Virtual CISO Moment dives into the stories of information security, information technology, and risk management pros; what drives them and what makes them successful while helping small and midsized business (SMB) security needs. No frills, no glamour, no transparent whiteboard text, no complex graphics, and no script - just honest discussion of SMB information security risk issues. Brought to you by vCISO Services, LLC, a leading provider of vCISO and information security risk management services. Visit https://vcisoservices.com to learn more. A Second Chance Publishing, LLC podcast.

Author

Greg Schaffer

Category

Technology

Podcast website

vcisopodcast.net

Latest episode

Jun 30, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

VCM Quick Strike for Monday, November 14, 2022 14.11.2022

KmsdBot, email server extortion, Fed requirements and ITAM, CMMC advice, ways data can be exposed, and a primer on pen testing - plus thoughts on when pen tests aren't exactly pen tests (and the SMB loses out). https://thehackernews.com/2022/11/new-kmsdbot-malware-hijacking-systems.html https://www.infosecurity-magazine.com/news/mass-email-extortion-claims-server/ https://itassetmanagement.net/202...

The Virtual CISO Moment Wrap Up for Friday, November 11, 2022 11.11.2022

Why phishing emails have typos, repeat ransomware demands, SMS used in banking attack, CISOs making job changes, Twitter CISO and CPO resign, plus some thoughts on the Twitter infosec exodus. https://securityboulevard.com/2022/11/why-do-phishing-emails-have-such-obvious-typos/ https://www.insurancejournal.com/news/national/2022/11/09/694534.htm https://thehackernews.com/2022/11/warning-this-widesp...

Throwback Thursday for November 10, 2022 - A Conversation with Anthony Scarola 10.11.2022

From July 26, 2022 - Anthony Scarola is an IT Governance, Risk, and Compliance (GRC) expert; has many years in cybersecurity; is a U.S. Army veteran; holds the CISSP; and is a virtual CISO. And he's writing a security book! Listen to his wisdom as it pertains to risk management and learn one mistake many may make when discussing risk with the c suite and board of directors.

VCMS4E56 - The RETR3AT Sessions - A Conversation with Rob Bowker 09.11.2022

Rob Bowker, Sales Director at EasyDMARC, explains the risks of email spoofing, the benefits of implementing DMARC in addition to DKIM and SPF, and how EasyDMARC helps to manage DMARC. Recorded at RETR3AT Cyber Conference Montreat College September 23, 2022.

The Virtual CISO Moment S4E55 - A Conversation with Jake Williams 08.11.2022

Jake Williams is a cybersecurity manager and aspiring CISO, currently pursuing his MBA. He is also well-versed in CMMC, and we dive into some elements of this somewhat confusing standard/requirement.

VCM Quick Strike for Monday, November 7, 2022 07.11.2022

National Guard to assist with election cyber security, supply chain stops train, predictions for 2023, MFA fatigue explored, and CEO sanctioned in breach, plus thoughts on the C-Suite and Board of Directors responsibility. https://www.politico.com/news/2022/11/04/nationa-guard-midterm-election-cybersecurity-00065236 https://www.securityweek.com/cyberattack-causes-trains-stop-denmark https://www.pr...

The Virtual CISO Moment Wrap Up for Friday, November 4, 2022 04.11.2022

2022 cybersecurity threat landscape report, election cybersecurity concerns, arrest in dark web market, five cybersecurity mistakes for businesses, and a primer on threat hunting - plus thoughts on career planning and management. https://www.enisa.europa.eu/news/volatile-geopolitics-shake-the-trends-of-the-2022-cybersecurity-threat-landscape https://www.helpnetsecurity.com/2022/10/31/election-cybe...

Throwback Thursday for November 3, 2022 - A Conversation with J.J. Powell 03.11.2022

From July 19, 2022 - J.J. Powell of Cyber Defense Group (https://www.cdg.io/) discusses his career journey from police officer to system administrator to CISO and now as leading virtual CISO services. He is also a pivotal component into my decision to leave corporate and become an independent vCISO - listen to find out what was "the straw that broke the camel's back" for me!

VCMS4E54 - The RETR3AT Sessions - A Conversation with Dan Bradley 02.11.2022

Dan Bradley, CIPP/E, CIPP/US, CIPM, is the Senior Associate General Counsel at Global Payments, Inc. and a former Federal Prosecutor. We discuss privacy regulations both for financial institutions and SMBs, including the importance of frameworks. Recorded at RETR3AT Cyber Conference Montreat College September 23, 2022.

The Virtual CISO Moment S4E53 - A Conversation with Christian Espinosa 01.11.2022

Christian Espinosa is the author of "The Smartest Person in the Room: The Root Cause and New Solution for Cybersecurity", Founder and CEO of Alpine Security, a cybersecurity engineer, certified high-performance coach, professor, and lover of heavy metal music and spicy food. He’s also an Air Force veteran and Ironman triathlete. He used to value being the “smartest guy in the room,” only to realiz...

VCM Quick Strike for Monday, October 31, 2022 31.10.2022

Midterm election caution, OpenSSL critical update, copper producer Aurubis attached, possible intrusion at Bed Bath and Beyond, Liz Truss potential phone hack, and thoughts about the risks of using personal devices for corporate business. https://www.reuters.com/world/us/complex-threat-environment-ahead-midterm-elections-top-cybersecurity-official-2022-10-30/ https://mta.openssl.org/pipermail/open...

The Virtual CISO Moment Wrap Up for Saturday, October 29. 2022 29.10.2022

Australia to increase breach fines, patients affected by breach do not have standing to sue, 22-year old vulnerability discovered, two POS malware used in breach, cyber insurance considerations from the NACD blog, and some thoughts on risk treatment. https://www.abc.net.au/news/2022-10-21/data-breach-fines-increase-after-medibank-optus-hacks/101564614 https://www.vitallaw.com/news/hipaa-d-kan-pati...

Throwback Thursday for October 27. 2022 - A Conversation with Johanan (Jo) Dixon 27.10.2022

From July 12, 2022 - Johanan (Jo) Dixon talks about life in the Marine Corps, as an MMA amateur fighter, and as a Title boxing instructor, and how these helped prepare him for his journey to cybersecurity and his current role with Halcyon (https://www.halcyon.ai/). And he's starting up a new podcast!

The Virtual CISO Moment S4E52 - A Conversation with Marci McCarthy 26.10.2022

Marci McCarthy is CEO and President at T.E.N. CEO and Chairman at ISE® Talent. She founded T.E.N.’s flagship program, the Information Security Executive® of the Year (ISE®) Program Series, which is lauded by the IT industry as the premier recognition and networking program for security professionals in the U.S. and Canada. She is a 2012 recipient of a 4th Congressional District of Georgia Citation...

The Virtual CISO Moment S4E51 - A Conversation with Albert Whale 25.10.2022

Albert Whale, Founder and CEO of IT Security Solutions, Inc and the developer of ITS Safe which provides real-time continuous protection at machine speed. He has over 30 years of experience with reducing the risk for business owners, minimizing their liabilities and overall risk. He has extensive experience in the techniques that criminal hackers use and identifies the probability and impact risks...

VCM Quick Strike for Monday, October 24, 2022 24.10.2022

"VSOC", nonprofit cybersecurity challenges, seven steps to defend healthcare agencies, workforce shortage, loss of GPS for flight navigation in Dallas, and some thoughts on aviation and navigation from my active pilot days. https://www.theregister.com/2022/10/18/ntt_denso_security_for_cars/ https://www.csoonline.com/article/3676668/altruism-under-attack-why-cybersecurity-has-become-essential-to-hu...

The Virtual CISO Moment Wrap Up for Friday, October 21, 2022 21.10.2022

Google forms COVID phish, US national cybersecurity strategy, Microsoft customer data breach, economic uncertainty and the effect on cyber risk, and skill resources and advice for CISOs - plus what I believe is an important certification for CISOs that is not talked about too often. https://www.bleepingcomputer.com/news/security/google-forms-abused-in-new-covid-19-phishing-wave-in-the-us/ https://...

Throwback Thursday for October 20, 2022 - A Conversation with William Birchett 20.10.2022

From July 5, 2022 - William Birchett, President of Logos Systems and creator of the vCISO Network, discusses the virtual CISO space including elements that make a successful vCISO, the biggest threat to SMBs (it's not ransomware!), and his future plans to help the vCISO field through Logos Systems, the vCISO Network, and other endeavors.

VCMS4E50 - The RETR3AT Sessions - A Conversation with Jon Sternstein 19.10.2022

Jon Sternstein is the Founder and Principal of Stern Security, a cyber security company headquartered in Raleigh, NC. He is co-author of the Cisco Press course titled “Security Penetration Testing (The Art of Hacking) LiveLessons”, holds many security certifications including: GIAC Penetration Tester and Certified Information Systems Security Professional (CISSP), is a featured cyber security expe...

The Virtual CISO Moment S4E49 - A Conversation with Keith Maune 18.10.2022

Keith Maune, Founder & COO at Acumen Technology, discusses his IT and cybersecurity path, from doing consulting work for companies needing website design and programming services, working after school and full-time during the summers, pursuing a BS and MBA while working full-time as co-owner and CIO of Advanced Network Solutions, earning a law degree, and launching Acumen Technology, a compreh...

VCM Quick Strike for Monday, October 17, 2022 17.10.2022

AMLBot cleans house, Windows Zero Day details, White and Black Hat, Magnibar ransomware, and SMBs feeling financial pain from county system attack. https://krebsonsecurity.com/2022/10/anti-money-laundering-service-amlbot-cleans-house/ https://www.hackademicus.nl/experts-disclose-technical-details-of-now-patched-cve-2022-37969-windows-zero-day/ https://www.bestcolleges.com/bootcamps/guides/white-ha...

From The Vault - Information Security Theater 14.10.2022

From January 1, 2020 Information security theater, improvements that look and sound good but make no real impact to overall security stance of an organization, can do more harm than good. Are you understanding the information security risks of your organization before designing and implementing controls?

The Virtual CISO Moment Wrap Up for Friday, October 14, 2022 14.10.2022

Update on Optus, why ji32k7au4a83 is a common password, Russia's version of GitHub, Lockbit used in attack, Malwarebytes new MDR, White House unveils IoT labeling initiative, and a new CMMC-focused podcast - plus a few thoughts on podcasts in general. https://www.cisc.gov.au/news-media/archive/article?itemId=955 https://www.gizmodo.com.au/2022/10/why-ji32k7au4a83-is-a-remarkably-common-password/ h...

Throwback Thursday for October 13, 2022 - A Conversation with Dick Wilkinson 13.10.2022

In today's Throwback Thursday episode from June 28, 2022, Dick Wilkinson, CTO and Co-founder of Proof Labs, discusses securing space, the transition to entrepreneur, the vCISO discipline, and more!

VCMS4E48 - The RETR3AT Sessions - A Conversation with Michelle Pupoh 12.10.2022

Michelle Pupoh is the Senior Director of Cybersecurity Education at the Carolina Cyber Center. She discusses the approach the center takes in training the next generation of cyber professionals, including the importance of ethics and soft skills. Recorded at RETR3AT Cyber Conference Montreat College September 23, 2022.

Listen to the The Virtual CISO Moment podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.