Greg Schaffer
The Virtual CISO Moment
The Virtual CISO Moment dives into the stories of information security, information technology, and risk management pros; what drives them and what makes them successful while helping small and midsized business (SMB) security needs. No frills, no glamour, no transparent whiteboard text, no complex graphics, and no script - just honest discussion of SMB information security risk issues. Brought to you by vCISO Services, LLC, a leading provider of vCISO and information security risk management services. Visit https://vcisoservices.com to learn more. A Second Chance Publishing, LLC podcast.
Author
Greg Schaffer
Category
Podcast website
Latest episode
Jun 30, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
The Virtual CISO Moment S3E1 - Information Security Theater 01.01.2020 7:44
Information security theater, improvements that look and sound good but make no real impact to overall security stance of an organization, can do more harm than good. Are you understanding the information security risks of your organization before designing and implementing controls?
The Virtual CISO Moment S2E12 - Information Security and Information Technology Security 13.12.2019 5:23
Information Security and Information Technology Security are not the same. If your program is focused on Information Technology Security only, you've got gaps.
The Virtual CISO Moment S2E11 - Information Security Fitness 24.11.2019 3:52
In order to stay healthy, we need to exercise regularly. To maintain our information security program's fitness, we need to exercise it as well.
The Virtual CISO Moment S2E10 - Information Security Policies 13.11.2019 8:38
Information security policies direct the governance of the information security program. What are elements of effective policies, and what mistakes do SMBs often make with their information security policy program?
The Virtual CISO Moment S2E9 - Quantitative Information Security Risk Assessments - Presentation 25.10.2019 50:40
Learn how quantitative information security risk assessments can help community institutions (and all small and midsized businesses). A presentation to the Bankers' Bank of the West Information Security for Community Institutions conference October 25, 2019.
The Virtual CISO Moment S2E8 - GRC 21.10.2019 4:42
Governance, Risk, and Compliance - how it can benefit information security for businesses of all sizes.
The Virtual CISO Moment S2E7 - What is a Virtual CISO? InfoSec Nashville 2019 27.09.2019 22:13
In this extended episode, vCISO Services principal Greg Schaffer speaks at InfoSec Nashville 2019 about what a virtual CISO is and how they help small and midsized businesses.
The Virtual CISO Moment S2E6 - Conversation at the National Cyber Summit 2019 21.09.2019 4:40
vCISO Services principal Greg Schaffer discusses the virtual CISO role in a short interview at the National Cyber Summit.
The Virtual CISO Moment S2E5 - OpenFAIR 04.09.2019 4:02
Greg discusses the announcement of vCISO Services, LLC's licensed quantitative information risk assessment offering based on The Open Group Open FAIR™ Body of Knowledge. https://www.prnewswire.com/news-releases/an-answer-for-cybersecurity-cost-exposure-300911336.html
The Virtual CISO Moment S2E4 - ISO 27001 Part 3 29.08.2019 7:16
Greg concludes a three-part series breaking down ISO 27001 and ISO 27002, international standards for information security. Part three dives into the second half of the ISO 27002 control requirements.
The Virtual CISO Moment S2E3 - ISO 27001 Part 2 19.08.2019 6:27
Greg continues a three-part series breaking down ISO 27001 and ISO 27002, international standards for information security. Part two dives into the first half of the ISO 27002 control requirements.
The Virtual CISO Moment S2E2 - ISO 27001 Part 1 14.08.2019 4:16
Greg begins a three-part series breaking down ISO 27001 and ISO 27002, international standards for information security. Part one lays out the history and a glimpse at the structure of ISO 27000 and why it's important for SMBs.
The Virtual CISO Moment S2E1 - What's in a Name? 07.08.2019 4:16
Taken from a Facebook Live video July 26th (hence the lower video quality), Greg explains why the Virtual CISO Minute is now the Virtual CISO Moment, talks about possible future use of the Facebook Live channel to help small and midsized businesses with information security topics, and invites current vCISOs or those interested in the space to join the Virtual CISO Exchange LinkedIn group at...
The Virtual CISO Moment S1E12 - The Rise of the Virtual CISO 31.07.2019 43:52
There is a growing rift between the information security “haves” and “have nots,” and the threat actors know that as well. Cyber criminals increasingly target small and midsized businesses (SMBs) because they know SMBs likely do not have information security programs as robust as those large organizations have in place. Nor do they have experienced information security leadership, as the average a...
The Virtual CISO Moment S1E11 - Career Genesis 31.07.2019 3:02
Thirty-four years ago, I worked as a porter (janitor) at a hotel in New Jersey. I took a year off between high school and college to decide where I wanted to direct my life - and to earn money for college. I promised myself that one day, when I had become successful, I would stay in that hotel. Recently it happened. I realized I learned an early lesson applicable to information security then. Watc...
The Virtual CISO Moment S1E10 - What is a Virtual CISO? 24.07.2019 1:32
You've heard the term, but what is a Virtual CISO, or vCISO? This week's Virtual CISO Minute explains
The Virtual CISO Moment S1E9 - Compensating Controls 17.07.2019 2:40
Compensating Controls: Is an audit exception regarding a failing primary control absolute? Maybe, maybe not. The risk may be mitigated by other methods - compensating controls.
The Virtual CISO Moment S1E8 - Veterans and Information Security 10.07.2019 1:56
The Nashville Technology Council's Veterans Peer Group helps veterans land civilian jobs and enhance their careers in IT and information security in the Nashville/Middle Tennessee region. SMBs should look to a veteran when trying to fill these positions.
The Virtual CISO Moment S1E7 - Quantitative Risk Assessments and SMBs 01.07.2019 2:49
Quantitative risk assessments and how they can help your SMB's information security posture.
The Virtual CISO Moment S1E6 - Qualitative Risk Assessments 28.06.2019 2:34
Qualitative risk assessments - the ones that produce those "heat maps" with the red (high risk), yellow (medium risk) and green (low risk) are a standard method for communicating information security risk. But they have limitations.
The Virtual CISO Moment S1E5 - The Importance of Information Security Risk Assessments 21.06.2019 2:40
Information security risk assessments - why are they important?
The Virtual CISO Moment S1E4 - SOC1, SOC2 Audit Reports Explained 31.05.2019 1:22
SOC1, SOC2, what do they mean for your small business? Find out in this week's installment of The vCISO Minute.
The Virtual CISO Moment S1E3 - The (Pragmatic) Need for Incident Response Testing 24.05.2019 1:44
A recent breach highlights the need for incident response testing, particularly about notification.
The Virtual CISO Moment S1E2 - Outdated Operating Systems 17.05.2019 1:15
Microsoft released a patch for out-of-support operating systems this week, but that's usually not the case. If your business requires running old operating systems, usually due to legacy software or systems, you need to reduce the risk running an outdated operating system brings by not relying on patches. Music by https://www.bensound.com/
The Virtual CISO Moment S1E1 - The Verizon Data Breach Investigation Report 10.05.2019 1:30
The annual Verizon Data Breach Investigation Report will come out soon. What is it, and how does it benefit small and midsized businesses?
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.