John Verry
The Virtual CISO Podcast
The Virtual CISO Podcast is a frank discussion that provides the very best information security advice and insights for Security, IT and Business leaders. If you’re looking for the latest strategies, tips, and trends from seasoned information security practitioners, want no-B.S. answers to your biggest security questions, need a perspective on how your peers are addressing the same issues, or just simply want to stay informed and proactive, then welcome to the show. Our moderator, John Verry, chats with industry thought leaders to ensure you have what you need to be confident in your security...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
GCC High Demystified: What CMMC Compliance Means for DIB Firms 18.12.2020 1:15:27
Should I migrate to GCC High? Do I have to? Are there alternatives? If you’re a DIB member and you are using Office 365 — as so many do — reaching CMMC Level 3 compliance is going to force you to make some difficult decisions. To help guide you through them, I invited Scott Edwards , President at Summit 7 Systems , onto the show to go over what CMMC Level 3 requires and how you can achieve it. Sco...
What DIB Firms Need to Know About the CMMC Interim Rule 15.12.2020 46:17
If you’ve taken the time to look through the DFARS Interim Rule… All 80+ (potentially) confusing pages of it... You might have some questions about how it applies to your business. Luckily, Scott Armstrong , Sr. Director, Cyber Risk, Analytics, and Insights at Exostar , has answers. In this episode, he and I discuss everything DIB firms need to know about the CMMC Interim Rule What we talked about...
The Secrets to Keeping Your SaaS Secure 16.11.2020 50:13
SaaS is a great business to be in. But whether you’re a startup or a mature company… Your product is only as good as your security. Today’s guest, Ryan Buckley, has advised SaaS firms for a number of years. He joins me to discuss how to address SaaS security and keep your product — and reputation — secure. What we talked about: - Why code repositories are an issue - Why product sec...
32. How IoT Is Shaping the Future of Cybersecurity 05.11.2020 1:09:35
The internet of things is taking off. IoT is bringing new innovations across the board… But it’s also bringing a new set of vulnerabilities. If you’re looking to make sure you’re secure in the world of IoT, I can’t think of anybody better to talk to than Aaron Guzman , Co Chair of the IoT Working Group, and John Yeoh , Global Vice President of Research, at Cloud Security Alliance . So, i...
31. A Brief History of NIST Guidance 22.10.2020 1:30:25
ISO 27001, CMMC, NIST 800-53… Keeping track of the myriad security guidelines can be tricky. Especially when you don’t know the “why” behind them. To help clear things up, in this episode, I speak with the preeminent expert on NIST guidelines, Dr. Ron Ross , Fellow at National Institute of Standards and Technology , and learn not just what the guidelines are — but how and why they came to b...
30. How to Beat the 6 Most Challenging CMMC L3 Requirements 06.10.2020 42:49
Preparing to achieve CMMC compliance may seem daunting. Especially in 6 challenging components. But we’re going to make them easy. In the latest The Virtual CISO Podcast episode, the tables are turned and I’m the one being interviewed. I explain these 6 problem areas and offer ways you can solve them. To hear this episode, and many more like it, you can subscribe to The Virtual CISO Po...
29. How COVID-19 Is Shaping Security’s Future w/Reg Harnish 29.09.2020 47:24
Though 2020 has felt decades-long already… We still haven’t had to deal with the long-term effects of the pandemic. But we will. The question is: Can your security? If you’re not sure, today’s guest will surely boost your confidence. Reg Harnish , Founder and CEO at Slingshot Cyberventures and Founder at GreyCastle Security , joins the show to walk us through the threats and opportunit...
28. Why 800-171 Compliance Isn’t Going Away Any Time Soon w/John Ellis 22.09.2020 44:45
CMMC is coming... But that doesn’t mean 800-171 compliance is out the window. In this episode, I catch up with John Ellis, Director of the Software Division at DCMA . We discuss: - How DCMA is conducting assessments - Why 800-171 compliance doesn’t just go away until CMMC - Why CMMC is so needed To hear this episode, and many more like it, you can subscribe to The Virtual CISO Podca...
27. How DevOps Took Over (& Why You Should Care) w/Jon Bass 11.09.2020 1:05:37
Not too long ago, DevOps seemed like a fringe buzzword… Now, it’s front-and-center. So, what is DevOps and why should you care? To answer, I invited Jon Bass , Co-Founder & CTO at Sym , onto the show. Jon’s expertise in the field makes him a perfect tour guide for the exciting — and often misunderstood — world of DevOps. Jon explains: - How DevOps moved from the fringe to the mainst...
26: How to Optimize Your ISMS w/Rich Stever 25.08.2020 1:03:47
When ISO 27001 is optimized for speed, it’s an amazingly effective and efficient way to manage security and compliance. Today’s guest is one of our most seasoned ISO experts in both client-facing and training roles. In this episode, I interview Rich Stever , IT Security Auditor at Pivot Point Security , about key artifacts for optimizing your ISMS. What we talked about: - Key artifacts of t...
25: CMMC Compliance & Continuous Monitoring Made Simple w/Chris Lank 17.08.2020 59:42
If your organization is in the DIB, CMMC compliance is a big deal. It’s probably the biggest thing to happen to information security in history. And you need to prepare. Your business could depend on it. That’s why for this episode, I sat down with Chris Lank , Founder and CEO at Ivis, a company offering a solution for monitoring any compliance, not just CMMC, year-round. Chris goes over...
24: Everything You Need to Know About ISO 27001 Audits w/ Ryan Mackie 11.08.2020 56:43
Prepping for an ISO 27001 audit can be a nerve-wracking process. But it doesn’t have to be. You just need to know what you’re getting into. And Ryan Mackie , as Principal and ISO Practice Director at Schellman & Company , is the perfect person to guide you through an audit. In today’s episode, he covers: Both stages of the ISO 27001 audit process What to expect on the day of the audit What...
23. Why Security Is So Important for a Growing SaaS w/ Jesse Nash 04.08.2020 56:35
If you have a growing SaaS company, security may be far down your list of priorities. I’ll be blunt… it shouldn’t. Security maturity can be make-or-break for SaaS clients and maybe even more importantly, SaaS investors. As a Partner at Reitler Kailas & Rosenblatt , Jesse Nash has a wealth of experience representing early-stage SaaS companies and venture capital investors, so he’s seen how se...
22. CMMC Training & Assessments: Rollout, Certification & Competition w/ Ben Tchoubineh 24.07.2020 50:13
If you are scrambling to figure out CMMC, you aren’t alone. It’s perhaps the most sweeping information security change for DoD contractors in history… And that comes with an assessment program dwarfing any other. As Member of the Board of Directors for CMMC AB , the accreditation body for CMMC, Ben Tchoubineh is one of the minds behind these assessments… just don’t call it an audit :). Ben came...
21. CMMC Compliance Doesn’t Have to Be Hard (or Pricey) w/ Sanjeev Verma 17.07.2020 1:22:47
If your company works with the DoD. You might be worried about CMMC compliance. But it doesn’t have to be hard or expensive. In this episode, I caught up with Sanjeev Verma , Co-Founder at PreVeil , a company offering one solution for CMMC’s requirement for encryption of email and file sharing that can save you money and hassle, while giving you unparalleled security. What we talked about: The sta...
20. Faster, Better & Cheaper Vendor Due Diligence Reviews w/ Kevin Hermosura 08.07.2020 38:11
Covid 19 has created lots and lots of challenges and opened our eyes to ones that lay dormant. One of the most stark realizations is how much we rely on our critical vendors. But how can you know a vendor is safe to work with, is reliable, and figure this out quickly and at a low cost? Enter ARM. Accelerated Risk Management Pivot Point Security’s answer to the need for rapid risk assessment. If...
19. Why Application Security is a Team Sport and How Your Team Can Win w/ Joe Manico 30.06.2020 1:07:52
If you’re a business leader, especially at a SaaS firm or if you’re a developer at a SaaS firm, this episode with Jim Manico will provide a ton of value. You'll hear practical advice on how to approach application security that even the most technically un-savvy listeners can understand. Joe Manico is an application security powerhouse. He is the Founder of an application security training compan...
18. IT & Security: How to Do More with Less w/ Jose Ciriaco 24.06.2020 52:50
Information security is a well easily fallen into. There is so much on the market. So many things to consider. It’s hard to determine what you actually need, and sometimes companies tend to just grab everything in sight to assure themselves that they are on point… Or not do enough for fear of wasting time and money on the wrong solutions. There are plenty of ideas, platforms, papers,...
17. CMMC Certification Audits—Can You Leverage ISO 27001? w/ Thomas Price 17.06.2020 43:02
If you want a glimpse into what one of your future CMMC audits will be like, this is the show for you. On this episode of The Virtual CISO Podcast, we welcome Thomas Price , Client Manager/IT and Information Security Auditor/Quality Management Professional at BSI . Working with clients to determine strategic direction, achieve objectives, and improve quality and service delivery, Thomas is one...
16. Why Buyers of Security Services Need to Leverage CREST w/ Ian Glover 09.06.2020 51:22
Who do you trust with your network? Would you give a random person access to the infrastructure that runs your business? Anyone with a computer and an Internet connection can set themselves up as a penetration testing or cyber incident response service provider. But what methods does your organization have in place for vetting an individual or company that you are potentially allowing unfe...
15. The OWASP Top Ten is Great, but is it Enough? w/ Andrew van der Stock 02.06.2020 45:31
We all have things we consider “the best”. Things we look to. Rely on. What happens when one of those old reliable, gold standard things that have been our go-to for so long winds up being #2, instead of #1? Andrew van der Stock , Senior Application Security Leader at OWASP Foundation stops by the podcast to dispel some industry myths about The OWASP Top 10. What we talked about: - Is...
14. How Computer Forensics Protects Your Data During Litigation w/ Brian Dykstra 26.05.2020 33:41
The word forensics usually makes us think of homicide, but it applies to computers, too. Computer forensics simply just means telling the story of what happened on a computer. In this episode, we hear from Brian Dykstra , President and CEO of Atlantic Data Forensics , about who needs computer forensics, when, and why. What we talked about: - The need for computer forensics is widespread a...
13. Why ISO 27701 is the Answer to Privacy Compliance w/ Debbie Zaller 19.05.2020 37:45
As the first data privacy certification available, ISO 27701 can greatly reduce the complexity of managing privacy, risk and proving compliance with regulations like CCPA, GDPR. Those organizations that already have a 27001 certification or are considering that certification can add on 27701 to change an Information Security Management System (ISMS) into an Information Security & Privacy Man...
12. Disaster Recovery, Business Continuity, and Data Resilience w/ Cosmo Gazzani 12.05.2020 36:52
Getting a flat tire is a disaster. Knowing where you keep the spare is disaster recovery. Changing a tire in under 7 minutes to get right back on the road is business continuity. In this episode, I interview Cosmo Gazzani , Director of Business Development at Continuity Centers and wekos , about information continuity and the importance of backing up your data. What we talked about: The nuance b...
11. OWASP ASVS: The Go-To Standard for Application Security w/ Daniel Cuthbert 05.05.2020 56:56
Your application is probably vulnerable. “But how?! We hired a company to pen test our application. They did a thorough test against the OWASP top 10!” On this episode of the Virtual CISO podcast, we talk with Daniel Cuthbert . He's one of the premier authors of the OWASP ASVS, and he says OWASP Top 10 is not enough. We chat about: Why the ASVS is so important Why we shouldn’t be putting all o...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.