John Verry
The Virtual CISO Podcast
The Virtual CISO Podcast is a frank discussion that provides the very best information security advice and insights for Security, IT and Business leaders. If you’re looking for the latest strategies, tips, and trends from seasoned information security practitioners, want no-B.S. answers to your biggest security questions, need a perspective on how your peers are addressing the same issues, or just simply want to stay informed and proactive, then welcome to the show. Our moderator, John Verry, chats with industry thought leaders to ensure you have what you need to be confident in your security...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
8 Ingredients for Baking Inclusivity into Your Culture 03.05.2022 48:41
Inclusivity and diversity aren’t just about who you hire — it’s about the culture you create. Sure, you can get talent from all walks of life, but if you haven’t built an inclusive culture… Well, good luck getting them to stick around. Today, I’m speaking with Deidre Diamond , Founder and CEO at CyberSN , who shares her 8-step framework for creating an inclusive culture in your organization. Join...
Becoming More Efficient w/ a Cloud-Native Approach 19.04.2022 38:50
What if you could be proactive in your approach to cloud data security rather than a reactive one once the attack has been made? This is exactly the solution our guest is providing at Panther Labs . We speak with Jack Naglieri , Founder & CEO, about the cloud-native approach and exactly why SIEMs are getting left behind. Join us as we discuss: Developing Panther & taking a different cloud-...
Use the CSA Cloud Controls to Maximize Your Security & Reduce Your Risk of Breach 05.04.2022 47:25
Even before the pandemic, the majority of businesses were already moving to the cloud. Now, it seems you can’t do business without it. Which means cloud security and compliance is more important than ever. That’s why I’m speaking to one of the authorities on cloud security, John DiMaria , Assurance Investigatory Fellow at Cloud Security Alliance , in today’s episode — to demystify cloud secur...
Ongoing Challenges in CMMC 29.03.2022 1:01:51
CMMC has come a long way in recent years… But organizations still face plenty of challenges navigating the guidance. What are the biggest hurdles and how can we reduce the confusion? To answer these questions, I’m joined by Kyle Lai , Founder and CISO of KLC Consulting , and Caleb Leidy , the CUI Protection and CMMC Consultant at Pivot Point Security . Join us as we discuss: Why CMMC scoping conti...
Is Open Source the Future of Endpoint Security 22.03.2022 39:22
Open source is a transparency issue. Being able to see what code is running on your computer — as well as what’s being monitored — gives you practically SaaS-level visibility across data, apps, and usage. In this episode, former open source developer Mike McNeil, CEO at Fleet Device Management, an open source company, talks with me about why open source is so imperative. Join us as we discuss: The...
The AWS Approach to Provable Security 15.03.2022 46:40
Traditionally, companies have relied on the promises of vendors when it comes to reaffirming their security stance. However, LimaCharlie has a far more radical approach—provable security. How are they doing it? In this episode, Maxime Lamothe-Brassard , LimaCharlie’s founder, explains the “AWS approach” the company employs for cybersecurity and how being born in the cloud provides infinite scalabi...
What Does the New ISO 27002 Update Mean for You? 01.03.2022 53:36
After years, ISO 27002 is finally here. What does that mean for your business? Luckily, the transition should be pretty seamless… But if you’re worried, have no fear because in today’s episode I’m joined by Danny Manimbo and Ryan Mackie , Company Principals at Schellman, who helped design the new standard. Join us as we discuss: - What’s new with ISO 27002 - What has stayed the same - The reas...
CMMC 2.0 & Continuous Compliance w/ Andrea Willis 15.02.2022 59:14
If you look around at what’s happening in the world of cybersecurity, you’ll notice one thing: Security never stops… Which means neither should compliance. That’s why I invited Andrea Willis, Senior Product Manager at Exostar ,an expert in continuous compliance onto the show to help you figure out how to stay compliant. Join us as we discuss: -The importance of continuous compliance -H...
8 Information Security Predictions for 2022 04.02.2022 19:49
We’ve had another bumpy year in 2021. So, what’s coming down the pike in 2022? And what impact will the ongoing information security challenges of today have on the world of tomorrow? In this episode, I answer those questions and more. Plus, I will assume the role of Nostradamus and make 8 information security predictions for 2022. To hear this episode, and many more like it, you can subscribe to...
Government Security Guidance: How We Got Here 28.01.2022 23:14
NIST, ISO, CMMC… If you’re beholden to government security guidance — and let’s face it, if you’re a company operating in the US, you very likely are — the list can be overwhelming at first. So, it helps to look back on where we’ve been and how we got where we are today. And in this solo episode, Our Host John Verry does exactly that — and hopefully, shine a light on what the guidance means and wh...
How Hardware Hackers Exploit IoT Vulnerabilities w/ Joe Grand 16.12.2021 1:00:12
You’ve probably heard the hype: IoT is the next frontier in the information revolution that promises to make all our lives easier… And that’s doubly true for hackers. In this episode, I’m joined by Joe Grand, also known as Kingpin, a computer engineer, hardware hacker, product designer, teacher, advisor, daddy, honorary doctor, TV host, member of legendary hacker group L0pht Heavy Industries, prop...
Bridging the Gap Between Security & Development Teams w/ Harshil Parikh 09.12.2021 49:15
There is an age-old conflict between security and development teams. Development teams are focused on time-to-market and packing features into the product. Security teams are often seen as speed bumps on the way to achieving those goals. How can we bridge the gap between the two? According to Harshil Parikh, CEO at Tromzo, new methodologies are presenting an incredible opportunity for security tea...
Why Cloud Is More Secure Than Your Average On-Prem Solution w/ Mark Richman 02.12.2021 41:16
What’s more secure? A cloud-based or on-prem document management system? It’s a question that gets asked a lot in our industry. So, I invited Mark Richman, Principal Product Manager at iManage, on to the show for a wide-ranging discussion on the topic. In this episode, we discuss: - Why a SaaS-based document management system is more secure than on-prem - Implementing compensating controls to miti...
How Configuration Management Makes Security Simple w/ Brian Hajost 23.11.2021 39:21
Configuration management is the best kept secret in security. Not only will it save time and money, it also helps you marry compliance and security — something we all need to get used to. The question is: Why isn’t everyone using it? Today’s guest, Brian Hajost, Founder and COO at SteelCloud, joins me on the show to give some compelling reasons why you should. In this episode, we discuss: - What c...
CMMC 2.0 is Here! Find Out What It Really Means for DIB and Non-DIB USG 12.11.2021 41:43
The US Department of Defense (DoD) has just announced CMMC 2.0, a new strategic direction for its cybersecurity program based on public comment and internal assessment. So what does it all mean? Many sources say that CMMC 2.0 is about "less requirements,"—but it's really much more about changing how the DoD will hold defense contractors accountable to the NIST SP 800-171 requirements that have bee...
How Simply Cyber Helps People Pivot to a Cybersecurity Career w/ Gerald Auger 10.11.2021 44:35
A lot of people want to break into cybersecurity. And why not? Where else can you have a blast, work with really smart people, earn a great living, have awesome job security, and do something truly impactful for the company you work for. However, it can be a particularly difficult industry to break into, especially if you don’t have the financial resources to pursue the education necessary to get...
Can You Benefit from Attack Surface Management? w/ Steve Ginty 29.10.2021 51:37
In a world where new vulnerabilities appear seemingly every minute, threat intelligence is more important than ever. And one of the most intriguing approaches to threat intelligence is attack surface management. To explain the ins and outs of attack surface management, I invited Steve Ginty, Director, Threat Intelligence at RiskIQ, onto the show. He shares the work RiskIQ is doing in the field and...
Why Continuous Compliance Matters More than Ever w/ Mosi Platt 21.10.2021 1:04:54
As public trust in technology erodes — for the first time — it’s clear that we need to reevaluate our approaches to security and compliance. The way we’ve been doing it is no longer working… But continuous compliance might. Today’s guest, Mosi Platt, Senior Security Governance, Risk, Compliance & Assurance Partner at Neflix , join s the show to explain why. In this episode, we discuss: - The b...
How HIPAA Compliant Email is Revolutionizing Healthcare w/ Hoala Greevy 06.10.2021 40:05
When it comes to healthcare InfoSec, it’s the Wild West. Most healthcare organizations just don’t have the necessary IT budgets to make it a priority. But it should be a priority. The truth is a large number of hospitals have been targeted by ransomware in the last few years. Today’s guest, Hoala Greevy , Founder and CEO at Paubox , shares how his company is arming healthcare organizations with H...
Private Practices: How to Prioritize Privacy in Your Organization w/ Jason Powell 27.09.2021 57:21
In the U.S., it’s easy to look at overseas privacy legislation like GDPR and conclude it’s a reaction to worrying data practices from today’s tech giants. In reality, European privacy legislation can trace its roots back to the nightmarish authoritarian regimes of postwar Europe — and the necessity of securing a future free from repeating these governmental abuses. That’s just one of the many priv...
Why Information Security Is Key to Business Strategy w/ Chris Dorr 16.09.2021 54:34
Chess legend Bobby Fischer once said that winning tactics flow from a superior position. Bobby Fischer would have made a great CISO. That’s because information security strategy is all about steering your business to a winning position that makes tactics easy. And it’s why your infosec and business strategies are entirely dependent on one another. My guest today, Chris Dorr , Virtual Chief Informa...
Head in the Clouds: Multi-Cloud Security & Governance w/ John Grange 10.09.2021 55:59
How well do you know what’s happening in your cloud? With so many people in an organization able to access it, managing and tracking every change can be a Herculean task. So, it’s no surprise that so many organizations need help tracking drift across their cloud networks. And the best person they could turn to is today’s guest, John Grange , Co-Founder and CTO at OpsCompass , a company making soft...
Can We Predict Security Threats w/ Machine Learning? w/ Johnna Verry 02.09.2021 40:01
Every CISO’s dreams is moving from reactive security to purely proactive security posture. In an era of big data and technological advancements in machine learning is this dream finally a reality? To find out, we charged today’s guest, Johnna Verry , Intern at Pivot Point Security , with putting machine learning to the test to see if it can really be the breakthrough we need in predictive security...
What People Get Wrong About ISO 27001 Compliance 26.08.2021 21:55
Just because ISO 27001 suggests a control, doesn’t mean you have to have it – in fact, you could be hurting yourself if you do by wasting money and have more trouble in an audit than you would otherwise. Your controls depend on your risk — not ISO suggestions. That’s just one of the many misunderstandings people have about the ISO 27001 standard. In this solo episode, host John Verry , CISO &...
Bridging the Gap Between Traditional Compliance & DevOPs w/ Raj Krishnamurthy 18.08.2021 36:20
Traditional compliance approaches have served us well for years… But they just don’t cut it anymore. We need an approach to compliance that moves at the speed of DevOps. Our guest today, Raj Krishnamurthy , is Founder, CEO and Engineer at ContiNube , where he is helping to bridge the gap between traditional compliance techniques and the agile, fast-paced world of DevOps. In this episode, we discus...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.