Greg Schaffer

The Virtual CISO Moment

The Virtual CISO Moment dives into the stories of information security, information technology, and risk management pros; what drives them and what makes them successful while helping small and midsized business (SMB) security needs. No frills, no glamour, no transparent whiteboard text, no complex graphics, and no script - just honest discussion of SMB information security risk issues. Brought to you by vCISO Services, LLC, a leading provider of vCISO and information security risk management services. Visit https://vcisoservices.com to learn more. A Second Chance Publishing, LLC podcast.

Author

Greg Schaffer

Category

Technology

Podcast website

vcisopodcast.net

Latest episode

Jun 30, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

The Virtual CISO Moment S4E30 - A Conversation with Anthony Scarola 26.07.2022

Anthony Scarola is an IT Governance, Risk, and Compliance (GRC) expert; has many years in cybersecurity; is a U.S. Army veteran; holds the CISSP; and is a virtual CISO. And he's writing a security book! Listen to his wisdom as it pertains to risk management and learn one mistake many may make when discussing risk with the c suite and board of directors.

VCM Quick Strike for Monday, July 25, 2022 25.07.2022

Rogers outage cause, 54 million Twitter accounts' information for sale for $3K, ransomware update, Entrust breached, an startups without a CISO are at a disadvantage - plus statistics, and why you need to both understand their context and source, using a well-known example of an information security "statistic" in the last article. https://twitter.com/atoonk/status/1550896347691134977 https://www....

The Virtual CISO Moment Wrap Up for Friday, July 22, 2022 22.07.2022

Ransomware infections and payments decline, CISO urges patching Windows 11 patch bug, more Chrome fixes, stress in cybersecurity, possibly regulating BGP, and commentary on the CU Intersect conference. https://www.darkreading.com/threat-intelligence/ransomware-attempts-flag-as-payments-also-decline https://threatpost.com/cisa-urges-patch-11-bug/180235/ https://www.forbes.com/sites/daveywinder/2022...

Throwback Thursday for July 21, 2022 - A Conversation with Chuck Sirois 21.07.2022

On this Throwback Thursday episode from March 29, 2022 - Email remains the most common vector for criminals to exploit. Chuck Sirois discusses how PhishFacts (https://phishfacts.com) can help SMBs identify misconfigured email configurations that criminals may leverage.

The Virtual CISO Moment S4E29 - A Conversation with J.J. Powell 19.07.2022

J.J. Powell of Cyber Defense Group (https://www.cdg.io/) discusses his career journey from police officer to system administrator to CISO and now as leading virtual CISO services. He is also a pivotal component into my decision to leave corporate and become an independent vCISO - listen to find out what was "the straw that broke the camel's back" for me!

VCM Quick Strike for Monday, July 18, 2022 18.07.2022

Shodan special offer, banks need to implement best practices, five key things from smal org CISOs, Netwrix Auditor bug, and on the road challenges. https://www.shodan.io/ https://fintechmagazine.com/banking/banks-need-best-practices-to-fight-rising-cyberattacks https://thehackernews.com/2022/07/5-key-things-we-learned-from-cisos-of.html https://thehackernews.com/2022/07/new-netwrix-auditor-bug-cou...

The Virtual CISO Moment Wrap Up for Friday, July 15, 2022 15.07.2022

Phishing campaign bypasses MFA, healthcare debt collection agency ransomware breach 1.9 million records, Log4Shell endemic, criminal hackers targeting Indian students, Florida Atlantic University received grant, and my cybersecurity path, including learning Python? https://threatpost.com/large-scale-hishing-bypasses-mfa/180212/ https://www.theregister.com/AMP/2022/07/13/19m_patients_medical_data_e...

Throwback Thursday for July 14, 2022 - The CISSP and the Virtual CISO 14.07.2022

On this week's Throwback Thursday from 3/22/2022 - The Certified Information Systems Security Professional, or CISSP, is considered by some to be the pinnacle of information security professional certifications, on par with the CPA. But why is that, and what differentiates it from other certifications? And why is it important for virtual CISOs to have and maintain this certification?

The Virtual CISO Moment S4E28 - A Conversation with Johanan (Jo) Dixon 12.07.2022

Johanan (Jo) Dixon talks about life in the Marine Corps, as an MMA amateur fighter, and as a Title boxing instructor, and how these helped prepare him for his journey to cybersecurity and his current role with Halcyon (https://www.halcyon.ai/). And he's starting up a new podcast!

VCM Quick Strike for Monday, July 11, 2022 11.07.2022

Rogers service interruption, hacking a Honda, the future of certifications, and Monday thoughts. https://www.reuters.com/business/media-telecom/rogers-communications-services-down-thousands-users-downdetector-2022-07-08/ https://blog.cloudflare.com/cloudflares-view-of-the-rogers-communications-outage-in-canada/ https://www.coguard.io/post/canada-rogers-outage-root-cause-analysis https://www.vice.c...

The Virtual CISO Moment Wrap Up for Friday, July 8, 2022 08.07.2022

Marriott breach third in four years, CISA alert for Maui ransomware, SMBs not leveraging MFA, free entry-level cybersecurity training, DoD bug bounty program, the illusion of short cuts, and a disturbing LinkedIn site allegedly distributing copyrighted cybersecurity books without author and publisher authorization. https://www.cyberscoop.com/marriott-data-breach-baltimore/ https://www.cisa.gov/usc...

Throwback Thursday for July 7, 2022 - A Conversation with Ed Carroll 07.07.2022

On this week’s Throwback Thursday from 3/15/22, Ed Carroll joins us to discuss many of the initiatives he's involved with, including Edison Marks to apply AI to help SMBs (https://edisonmarks.com/), the Carolina Cyber Center to help with information security in North Carolina and beyond (https://carolinacybercenter.com/), and an update on the RETR3AT cyber security conference at beautiful Montreat...

The Virtual CISO Moment S4E27 - A Conversation with William Birchett 05.07.2022

William Birchett, President of Logos Systems and creator of the vCISO Network, discusses the virtual CISO space including elements that make a successful vCISO, the biggest threat to SMBs (it's not ransomware!), and his future plans to help the vCISO field through Logos Systems, the vCISO Network, and other endeavors.

VCM Quick Strike for Monday, July 4, 2022 04.07.2022

Ransom returned with gains, cyber risks in space, NIST CSF 2.0 coming, HackerOne employee claims bug bounties for themselves, bug bounty programs offer hope for cyber skills gap, and thoughts on another approach to closing that gap. https://www.dw.com/en/dutch-university-wins-big-after-bitcoin-ransom-returned/a-62337229 https://cybernews.com/editorial/in-space-cutting-losses-invite-cyberattacks/ h...

The Virtual CISO Moment Wrap Up for Friday, July 1, 2022 01.07.2022

Microsoft Office 365 Office feature could enable ransomware infection, MedusaLocker alert from CISA, California breach of gun enthusiasts' PII, human error remains the top security issue according to a SANS report, and a tribute to an extraordinary man.  https://www.itsecurityguru.org/2022/06/23/microsoft-office-365-feature-could-help-ransomware-attackers-infiltrate-cloud-files/ https://www.c...

Throwback Thursday for June 30, 2022 - A Conversation with Craig Sandman 30.06.2022

On this week’s Throwback Thursday from 3/8/22, Craig Sandman of Symbol Security (https://symbolsecurity.com/) and vCISONews (https://www.vcisonews.com/) joins us to discuss the importance of effective security awareness training for SMBs and the virtual CISO role.

The Virtual CISO Moment - A Conversation with Dick Wilkinson 28.06.2022

On this episode of The Virtual CISO Moment podcast, Dick Wilkinson, CTO and Co-founder of Proof Labs, discusses securing space, the transition to entrepreneur, the vCISO discipline, and more!

VCM Quick Strike for Monday, June 27, 2022 27.06.2022

Japanese man loses USB stick with citizen data after night of drinking, ransomware more about extortion, MITEL VOIP exploit, "the hateful eight" ransomware groups, new Colorado facia recognition law, and thoughts on the Offensive Security free Kali Linux Twitch stream training after two sessions. https://www.bbc.com/news/world-asia-61921222.amp https://www.theregister.com/2022/06/25/ransomware_gan...

The Virtual CISO Moment Wrap Up for Friday, June 24, 2022 24.06.2022

Pegasus in Europe, Log4Shell affecting VMware, voicemail scam (because it works), SMS Bomber malware, and how financial firms can benefit from a vCISO - plus more commentary and analysis of the vCISO field. https://thehackernews.com/2022/06/nso-confirms-pegasus-spyware-used-by-at.html https://www.helpnetsecurity.com/2022/06/24/log4shell-vmware-horizon/ https://threatpost.com/voicemail-phishing-sca...

Throwback Thursday for June 22, 2022 - A Conversation with David Baker 23.06.2022

This week's Throwback Thursday episode is from March 1, 2022 - Chief Information Security Officer David Baker gives insight into the challenges of an SMB CISO. Guest opinions are their own and not the views of their employer.

The Virtual CISO Moment S4E25 - A Conversation with Nick Santora 21.06.2022

Nick Santora, CEO of Curricula ( curricula.com ), discusses information security awareness and how Curricula uses storytelling to make both short term and long term impressions, resulting in increased security across the organization. He also discusses his path to entrepreneur, challenges in the SMB infosec awareness space, and "wisdom walks"!

VCM Quick Strike for Monday, June 20, 2022 20.06.2022

Russian botnet shut down, CFOs see cybersecurity gaps, security lapses in SMBs, university students defeat 21st century vehicle boot, and a free pen testing class coming soon to Twitch! Plus my thoughts on this past weekend's #infosec Twitter conference issue. https://thehackernews.com/2022/06/authorities-shut-down-russian-rsocks.html https://www.cfodive.com/news/cfos-ceos-see-cybersecurity-gaps-a...

The Virtual CISO Moment Wrap Up for Friday, June 17, 2022 17.06.2022

Internet Explorer is retired, risks with IoT, Facebook Messenger phish, diving into the Veeam ransomware report, and one of the hardest things I've had to do in my professional career. https://www.cnn.com/2022/06/15/tech/internet-explorer-dead/index.html https://www.forbes.com/sites/forbestechcouncil/2022/06/16/cybersecurity-and-risk-management-in-the-internet-of-things/ https://threatpost.com/ace...

The Virtual CISO Moment S4E24 - A Conversation with Matt Santill 14.06.2022

Matt Santill, Founder and CEO of Cyber Security Services https://www.cybersecurityservices.com/ discusses the challenges of a vCISO, what is the most significant business risk, how he became interested in information security, and his career progression to CISO and on to business owner.

VCM Quick Strike for Monday, June 13, 2022 13.06.2022

A third of organizations hit by ransomware were forced to close temporarily or permanently, job cuts hit cybersecurity industry despite surging growth from ransomware attacks, four signs you may be ignoring your health for your career, and Cyber Security for Small Organisations webinar. https://www.techrepublic.com/article/organizations-hit-by-ransomware-shut-down/ https://www.cnbc.com/2022/06/10/...

Listen to the The Virtual CISO Moment podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.