John Verry
The Virtual CISO Podcast
The Virtual CISO Podcast is a frank discussion that provides the very best information security advice and insights for Security, IT and Business leaders. If you’re looking for the latest strategies, tips, and trends from seasoned information security practitioners, want no-B.S. answers to your biggest security questions, need a perspective on how your peers are addressing the same issues, or just simply want to stay informed and proactive, then welcome to the show. Our moderator, John Verry, chats with industry thought leaders to ensure you have what you need to be confident in your security...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
A Guide for Validating Your Security Process w/ John Verry 11.08.2021 35:43
In this special episode, we’re sharing a guest appearance John made on The Perfect Storm . During that episode, he shared how Pivot Point Security helps companies achieve security and compliance throughout different regulatory frameworks and a three-part process for validating your security processes. Topics covered: -What services Pivot Point Security offers - Helping clients understand the impor...
Governing Cybersecurity: A Process for Becoming Provably Secure & Compliant w/ John Verry 04.08.2021 30:52
Today’s special episode was inspired by a conversation we had with a then potential, now current client of ours at Pivot Point Security . In discussing our Virtual CISO offering, we described our tried-and-true process for helping a client become provably secure and compliant. He loved it and wanted us to train him and his team on it. We've since had a similar conversation with a couple of boards....
The Cybersecurity Executive Order: What You Need to Know w/ Scott Sarris 27.07.2021 54:06
In the wake of the SolarWinds fiasco, a new executive order mandates practices to prevent future attacks… How well does it address the threats? And what does it mean for you? To answer these questions, I invited Scott Sarris , Executive Vice President of Digital Transformation and Cybersecurity Advisory Services at Aprio , onto the show. Together, we break down the new EO into its most important c...
Your Passwords Are Failing You w/Josh Amishav-Zlatin 20.07.2021 40:46
By the time you think of a ‘new’ password, attackers already have a way to crack it. Josh Amishav-Zlatin , Founder & Technical Director at BreachSense , is here to reveal the ugly truth about passwords, the risks they present, and how you can mitigate those risks. What we talked about: - Breach timelines and scales of impact - How breaches work and how they’re identified - Is 2FA/MFA enough to...
Information Governance w/David Gould 08.07.2021 35:25
Information governance is the solution to that irrational fear of deletion we all experience from time to time. Expert in the field and Chief Customer Officer at Encompaas , David Gould , breaks it down for us in the latest episode of Virtual CISO. What we talked about: - What is information governance? - Data mapping potential and pitfalls. - The fear of deletion. - Value creation and information...
DIBCAC & CMMC Audit Prep w/ George Perezdiaz & Caleb Leidy 01.07.2021 41:41
Are you ready for your DIBCAC/CMMC audit? Let’s make sure. We’re speaking to two of our best Security Consultants from right here within our ranks at Pivot Point Security . Joining me are George Perezdiaz , CMMC / NIST Security Consultant, & Caleb Leidy , CMMC Consultant/Provisional Assessor. What we talked about: How to prepare for your DIBCAC/CMMC audit. What can you expect from an audit? Ge...
Trust Is a Vulnerability: 5 Steps on the Path to Zero Trust with John Kindervag 25.06.2021 1:00:33
How do you quantify trust? Is it something that can be digitized? In the world of cybersecurity, trust is a vulnerability. What we need is Zero Trust. That’s why I am so excited to speak with my latest guest, John Kindervag , Senior Vice President of Cybersecurity Strategy and Group Fellow at ON2IT Cybersecurity , who pioneered the concept of Zero Trust a decade ago — even if the world is only cat...
You Are a Target: Assessing Cybersecurity Risk with Dr. Eric Cole 16.06.2021 47:59
Whoever propagates the rumor that the goal of cybersecurity is to prevent all attacks deserves to be punched in the face. The goal of cybersecurity is timely detection and damage control. In this episode, we interview Dr. Eric Cole , Founder and CEO at Secure Anchor Consulting and author of, most recently, Cyber Crisis , about killing unprofitable cybersecurity myths. We also discussed: - Believin...
CMMC Assessments Are Here: What You Need to Know with Stacy High-Brinkley 10.06.2021 52:43
In the latest episode, Stacy High-Brinkley , VP of Compliance Solutions at Cask , shares what you need to know about the coming CMMC assessments. To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podcast here . If you don’t use Apple Podcasts, you can find all our episodes here . Listening on a desktop & can’t see the links? Just search for The Virtual CISO Pod...
Everything You Need to Know About StateRAMP with Leah McGrath 03.06.2021 49:54
The federal government has FedRAMP to manage security authorizations for cloud service offerings. But cyber attacks don’t stop at the federal level. State and local governments are under attack too. How can we create a process for cybersecurity verification of cloud service providers that lifts the cyber posture of state and local governments and the providers who serve them? To answer that questi...
How EDR & NDR Help You Make Better Security Decisions with Chris Neyhuis 26.05.2021 1:09:38
Remember those halcyon days when you could just stick an antivirus on your desktop and not worry — before all these confusing initialisms like EDR and NDR…. Well, turns out, they aren’t as complicated as you may think. And I can’t think of anyone more qualified to explain why than Chris Nyhuis , President and CEO at Vigilant , who joins the show to shine some light on why the old-fashioned AV is s...
How PreVeil Drive Makes Storing and Sharing Data More Secure with Sanjeev Verma 20.05.2021 51:06
PreVeil Drive is a cloud service that lets users encrypt, store and share their files for CMMC Compliance and personal use. Unlike other cloud services such as Dropbox and OneDrive, PreVeil uses end-to-end encryption which ensures that only intended recipients can access their files. In this episode of The Virtual CISO, we interview Sanjeev Verma , Co-Founder & Chairman at PreVeil , about usin...
Lessons Learned in Our Initial 27701 Certification Audits 10.05.2021 44:36
ISO-27701 is an exciting new standard. But it comes with a learning curve for all of us — clients, consultants, and auditors. In this episode, we’ll discuss some of the lessons we’ve learned in our initial audits so you can, hopefully, benefit from our teething pains. That’s why I invited today’s guests, Andrew Frost , GRC Consultant, and Aurore Watts , GRC and Privacy Consultant, here at Pivot Po...
Using your ISO 9001 Management System to Simplify CMMC Certification 28.04.2021 47:48
John Laffey , Program Manager at Perry Johnson Registrars, Inc. discusses the cornerstones of an information security management system from the perspective of a management system auditor. - Context: the boundaries, the scope, the data, the people, the systems, and the stakeholders, - Leadership: driving the entire process, continuing to champion it and making sure resources are available. - Plann...
How to Communicate Across Departmental Divides 20.04.2021 40:48
Have you ever wished that there was some sort of Star-Trek universal translator device for communicating your department’s needs to the C-Suite? Well, the technology isn’t quite there yet, but today’s guest offers the next best thing. John Sheridan , Co-Founder at Agency Performance Systems , joins the show to share the secrets to interdepartmental communication. What we talked about: - What your...
MSPs, MSSPs & Validation: What You Need to Know 13.04.2021 1:09:15
Gone are the days when every company had their own internal IT department. We’re well into the era of Managed Service Providers. But how do you find the right one for your business? In this episode, Host John Verry speaks with Charles Weaver , Co-Founder at MSP Alliance , covers everything you need to know about MSPs — and what to know if you are one. They discuss: - The importance of validating y...
Why CMMC Is the Most Significant Standard of all Time 09.04.2021 54:28
With the proliferation of so many information security standards, are we nearing a breaking point? In the end, which standard will win? In this episode, John Verry , Founder of Pivot Point Security , answers these questions and more in a guest appearance on the Encrypted Economy Podcast . John covers: - The basics of CMMC - Why CMMC is the most significant standard in InfoSec’s history - Whether w...
CMMC Level 1: An Overview 01.04.2021 31:22
Let’s talk about the Cybersecurity Maturity Model Certification, or CMMC. What is it, why should you care about it, and how do you know if it’s going to impact your business? While the industry has always known that CMMC certification was going to move beyond the Defense Industrial Base (DIB,) we assumed it was going to likely be towards the end of 2021, likely into 2022 and 2023. But it’s gro...
Solutions to Security, Compliance, and Technology Challenges in Aerospace 16.03.2021 42:17
Manufacturing tends to resist new technology. Not aerospace, though. It's on the cutting edge. In this episode of The Virtual CISO Podcast, John Virgolino , President/CEO at Consul-vation, Inc. & CEO at SENT, discusses what makes the aerospace sector different from technology and security perspective. John discusses: - Why making security part of your culture is key - The security challenges f...
CMMC Level 3: What Government Staffing Agencies Need to Know 09.03.2021 21:32
In this episode of The Virtual CISO Podcast, host John Verry , CISO and Managing Partner at Pivot Point Security go over everything government staffing agencies need to know about CMMC Level 3 requirements. John outlines: - How to tell if you have CUI in your environment - Whether your FCI can become CUI - If you need (or want) CMMC Level 3 compliance - The 3 steps to take when it comes to CMMC Le...
The ISVS: What You Need to Know 04.03.2021 50:29
These days, everything is connected to the internet. Whether it’s your car, your light bulbs, your microwave, your pacemaker, or your cochlear implant, it’s all being run and dictated by the internet. And with that brings a whole new set of concerns. Where you used to just have to worry about keeping your bank account secure, or your home wifi network secure, now all of a sudden you have to worry...
FedRAMP: What You Need to Know 26.02.2021 51:30
Are you looking to get your product authorized for use by federal agencies? Then you probably need to understand FedRAMP, how it works, and, most importantly, whether it applies to you. In this episode, I chat with Stephen Halbrook , Partner and Government Compliance Specialist at Schellman & Co , who answers the most common questions about the government security assessment. He answers: - Wha...
How Data Privacy Standards Affect Your Business 02.02.2021 1:24:34
Privacy is changing. Across the globe, new standards are recognizing it as a fundamental human right. But between GDPR, CCPA, and all the other standards popping up, figuring out all your data privacy obligations can be quite the challenge. That’s why I invited Dyann Heward-Mills , Lawyer and CEO of HewardMills , onto the show to discuss the challenges data privacy standards present — and how you...
Should You Invest in a GRC Tool for Security & Compliance? 21.01.2021 1:02:08
Getting your ducks in a row for a GRC audit can be a huge undertaking. Especially when you get compliant for the audit, then don’t look at it again until the next one rolls around. If this sounds familiar, you may have wondered whether investing in a GRC tool is worth it. In this episode, Craig Unger , Founder and CEO at HyperProof , shares all the information you need to decide whether investing...
CMMC Compliance: The Nuances You Should Know 12.01.2021 54:28
The DFARS interim rule that went into effect on November 30th has a lot of nuances to it — and many out there have questions about how it applies to them. In this episode, I sit down with Corbin Evans , Principal Director, Strategic Programs at National Defense Industrial Association , to get answers to some of the most common questions about these CMMC nuances, including: - What do DIB orgs with...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.