John Verry
The Virtual CISO Podcast
The Virtual CISO Podcast is a frank discussion that provides the very best information security advice and insights for Security, IT and Business leaders. If you’re looking for the latest strategies, tips, and trends from seasoned information security practitioners, want no-B.S. answers to your biggest security questions, need a perspective on how your peers are addressing the same issues, or just simply want to stay informed and proactive, then welcome to the show. Our moderator, John Verry, chats with industry thought leaders to ensure you have what you need to be confident in your security...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Ep 110: Understanding TISAX (Trusted Information Security Assessment Exchange) 31.01.2023 33:00
Trusted Information Security Assessment Exchange (TISAX) is a vendor due diligence standard used in the automotive industry to verify that third-party suppliers’ cybersecurity programs provide adequate protection for the information the automotive supplier shares. In this episode, your host John Verry, CISO and Managing Partner at Pivot Point Security, sits down with Ed Chandler, Account Executive...
Ep 109: Understanding How Cybercriminals Operate Can Protect Your Business 17.01.2023 45:39
In today’s cyber landscape, business leaders and security professionals need every edge they can gain to better protect their organizations and plan their defense against attackers. . Why do hackers do what they do? What are they trying to steal from you? Who do they partner with to make money and avoid getting caught? In this episode, hosted by John Verry, CISO and Managing Partner at Pivot Point...
Ep 108: Understanding the Legalities Around CUI 03.01.2023 51:05
Orgs in the DIB need to protect CUI in alignment with the NIST 800-171 cybersecurity standard—and soon the Cybersecurity Maturity Model Certification (CMMC) requirements—or face legal and compliance penalties as well as potential lost business. To clarify the biggest questions and reveal the most dangerous unknowns in the convoluted realm of CUI, your host John Verry, Pivot Point Security CISO and...
Ep 107: An AWS Security Guru’s Recommendation for Securing your AWS Infrastructure 20.12.2022 47:57
Over 90% of security breaches in the public cloud stem from user error, and not the cloud service provider. Today, your host John Verry sat down with one of Amazon Web Services (AWS) own Temi Adebambo, to understand what is going wrong with public cloud security, and how you can eliminate your biggest risks. This episode features Temi Adebambo, Head of Security Solutions Architecture at Amazon Web...
Ep 106: Strategies to Manage Cybersecurity through an Economic Downturn 13.12.2022 23:50
Managing Cybersecurity through an Economic downturn is no easy task. With increasing concerns on how to stay secure and compliant in a down economy, John Verry tackles this podcast himself giving you his ten best fundamental practices. This episode features your host John Verry, CISO & Managing Partner, from Pivot Point Security, who provides answers and explanations to a variety of questions...
Ep 105: Solving the Problems of Cloud Native Apps. 29.11.2022 34:55
Building Cloud Native Applications can bring about many operational and security problems. Today, we sat down with an expert in this field to talk about building cloud native applications, and deploying applications that are secure in the cloud. This episode features Fausto Lendeborg, Co-Founder & CCO, from Secberus, who provides answers and explanations to a variety of questions regarding Bui...
Ep 104: Is Digital Business Risk Mgt. The Future of ASM 15.11.2022 46:14
Digital Business Risk Management helps companies track and disrupt the most advanced bad actors. Team Crymu specializes in Digital Business Risk Management & Attack Surface Management, giving clients insight and help relating to cyber threats. This episode features David Monnier, Chief Evangelist and Team Cymru Fellow, from Team Cymru, who provides answers and explanations to a variety of que...
Ep 103: The Complexity of Deploying a Secure Application in the Cloud 01.11.2022 50:30
Governance, Risk, and Compliance (GRC) platforms can be tricky to construct. Today, we sat down with an expert in this field to talk about building and deploying secure applications in the cloud. This episode features Jeff Schlauder, Information Security Executive, from Catalina Worldwide, who provides answers and explanations to a variety of questions regarding deploying applications securely in...
Ep 102: The Intersection of Privacy and Security 25.10.2022 38:55
You cannot have privacy without security. While they once existed quite distinct from one another, they are now so delicately woven that they are nearly indistinguishable. Over time, the GDPR has cemented the relationship between physical security and information security, and now, it’s incorporating data privacy. This compliance triad has become the new normal for businesses everywhere– but what...
Ep 101: Most Asked CMMC Questions 14.10.2022 47:12
CMMC (Cybersecurity Maturity Model Certification) can raise many red flags and concerns - As CMMC rulemaking approaches in 2023, we take a break from our normal podcast and answer the most asked CMMC questions to date to help ease the unknown. This episode features George Perezdiaz, FedRisk Practice Lead, with Pivot Point Security, who provides answers and explanations to a variety of questions we...
Ep 100: The Two Audiences For Privacy & How They Drive Data Collection 13.09.2022 36:43
This marks our 100th episode of The Virtual CISO and an insightful journey into having the opportunity to have frank discussions with thought leaders that provide the very best information security advice and insights. I am happy to have invited Dimitri Sirota , CEO & CoFounder of BigID , to walk through BigID’s approach to privacy, security, and data governance on this momentous episodic occ...
Unpacking Critical Elements of Supply Chain Risk Management 30.08.2022 46:11
Supply chain risk management can prove to be a slippery slope—why should you take pains to conduct a proper risk assessment, and how do they impact IT and business continuity? From international restrictions to balancing generic and specific risk assessments, any guidance is welcome in the world of supply chain management. I invited Willy Fabritius , Global Head of Strategy & Business Develop...
Breaking Down the Latest in Software Security Standards & the Impact on SaaS Businesses 16.08.2022 37:45
What are the merits of the Software Assurance Maturity Model (SAMM), and how does it differ from the Application Security Verification Standard (ASVS) model? And why should you care? From design to operations, there are several crucial considerations to hold regarding business functions and use cases. I invited Taylor Smith , Application Penetration Testing Lead at Pivot Point Security , onto the...
What You Need to Know about APIs and API Security 09.08.2022 43:35
Application development is moving from a web-centric world to an API-centric world. If you’re wondering what that looks like, what the security implications are and what an API is, you’re in the right place. There is no shortage of new application security strategies to familiarize ourselves with as cybersecurity adapts to changing times. That’s why I invited Rob Dickinson, CTO at Resurface Labs ,...
How to Measure the Value of Information Security 02.08.2022 30:14
Most recognize the value preservation in cybersecurity. But forward thinking professionals also see the value creation in having a secure information posture. Cybersecurity is the foundation of preserving sensitive data and providing peace of mind but does it create value for the organization and if so, how do we measure that value? Tracking the return on investment on cyber security can be challe...
Understanding NIST’s Secure Software Development Framework 26.07.2022 45:55
What exactly is a Software Development Life Cycle, and how does NIST’s Secure Software Development Framework impact that cycle and your organization? Of note, the SSDF will definitely impact you if your software is used by the US Government and will likely impact you even if it isn’t. There are a few choice practices that can help make sense of these two critical processes and provide the highest...
US Gov. Cybersecurity Roadmap: Where it came from and Where is it Going? 19.07.2022 58:10
Today, information is worth more than riches. The new currency is data. With this being true, the state of cybersecurity within the upper branches of the government was shockingly under-prepared. In this episode, I speak with Mark Montgomery , the former Executive Director of the Cyber Solarium Commission, about the report the commission published in March 2020 and how that document has influenced...
Confronting the Wild West of Database Security 12.07.2022 47:05
Don’t wait for an emergency; secure your database correctly right out of the gate. Think of everything outside of your database as the wild west. What can you do to create the most controlled environment possible for all of your most sensitive data? I invited Robert Buda , President of Buda Consulting, Inc, and an expert in database technology, onto the show to help us learn the value of databas...
Bridging the Gap Between Cybersecurity and the Business World 28.06.2022 46:05
Ron Gula , President and Co-Founder of Gula Tech Adventures , has a very specific goal: To defend the country in cyberspace by investing in companies and nonprofits that help close the gap in technology and the workforce. He also knows that in order to successfully achieve this goal, organizations must understand the basics of data protection. Today, Ron joins the show to talk about the mindset...
Legal and Infosec strategies to deal with exploding Cyber Liability Insurance premiums 21.06.2022 36:59
There’s no denying that cybersecurity risks in the workplace have increased exponentially in recent years. From the pandemic causing employees to work from home to Russia’s invasion of Ukraine, organizations are more vulnerable than ever. That’s why it’s crucial to understand how to best protect yourself and your business. On this episode, Eric Jesse , Partner at Lowenstein Sandler LLP , joins the...
Important Clarifications on CMMC v2 from CMMC Day May 9, 2022 14.06.2022 16:50
To invest in CMMC or to not invest in CMMC, that is the question. CMMC (Cybersecurity Maturity Model Certification) is a lofty yet necessary investment for the Defense Industrial Base. With all signs pointing to May 2023 for when we can expect CMMC to be included in contracts, anyone who is considering CMMC should do it sooner rather than later as implementing any comprehensive cyber security prog...
The Past, Present and Future of Cybersecurity From the Viewpoint of a Venture Capitalist 07.06.2022 50:59
Alberto Yépez joins the show to share his perspective as a venture capitalist working to help entrepreneurs build Cybersecurity businesses. He started his wildly successful career at Apple and he is now the Co-Founder and Managing Director at Forgepoint Capital . Join us as we discuss: Information security challenges from the 2000’s that we still face today Alberto’s experience working at Apple...
Understanding Attack Surface Management and How It Applies to Your Cyber Security Strategy 24.05.2022 36:30
We’ve spent the last two and a half years with rapidly rising cloud adoption. It was a rocket ship before that, but the COVID-19 pandemic has only accelerated it and caused everybody to scramble. We’re still trying to play catch up and get equivalent security treatments for people working remotely to the folks working in the office. Every client has concerns about their current exposure, which is...
The Convergence of Physical & Cyber Security and the Impact to Cyber Security Professionals 17.05.2022 25:27
As technology advances, there will always be new threats from malicious actors seeking to exploit these advancements — whether that be in the digital realm or physical. With technologies increasingly blurring the lines between the two, today’s security professionals must adapt as the sectors of physical security and cyber security converge into one. Today’s guest, Chris Ciabarra , Co-Founder and C...
What CMMC 2 Guidance Means for Managed Service Providers (MSPs) 10.05.2022 49:01
As the implementation of CMMC by the DIB picks up pace, the frequently shifting requirements can be daunting — especially when the guidance is already so complex. And that’s doubly true for managed service providers (MSPs), who have to contend with some of the most confusing CUI requirements. In today’s episode, making his 3rd guest appearance, I’m joined by Caleb Leidy , CUI Protection and CMMC C...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.