CISO Stories Podcast (Audio) cover art

All Episodes

CISO Stories Podcast (Audio) — 229 episodes

#
Title
1

Beyond the CVE Count: The Real State of Vulnerability Management - Charles Loring - CSP #228

2

Attack Surface Management - Matt Lea - CSP #227

3

Cloud Security Meets AI: What CISOs Need to Govern Before They Scale - Brent Neal - CSP #226

4

Critical Infrastructure: The Risk Hiding in Plain Sight - Jason Manar - CSP #225

5

IAM for MSSPs: The Hidden Risk of Blind Trust - Dustin Sachs - CSP #224

6

Cloud Security: The AI Effect & How to Proceed - Richard Marcus - CSP #223

7

From Alerts to Action: Making Public–Private Threat Intel Actually Useful - Ian Washburn - CSP #222

8

Beyond Vendor Risk: Real-Time GRC, AI, and Protecting App User Data - Jadee Hanson - CSP #221

9

Keys Without People — John Heasman on Cleaning Up Non-Human Access - John Heasman - CSP #220

10

Agents at the Door: Vetting Non-Human Identities in External IAM - Rakesh Soni - CSP #219

11

ATT&CK → ATLAS: A CISO's Blueprint for AI Governance - Sandy Dunn - CSP #218

12

Security Awareness Through Trust and Influence - Jennifer Selby Long - CSP #217

13

OT on the Frontlines: Threat Intelligence You Can't Ignore - Dawn Cappelli - CSP #216

14

Reimagining Security Operations: SOC as a Service and the Role of AI - Kevin Nikkhoo - CSP #215

15

From Diagram to Cloud: Rethinking Cloud Security in an Age of Uncertainty - Yogita Parulekar - CSP #214

16

Empowering Developers: Fostering a Culture of Security in AppSec - Danielle Ruderman - CSP #213

17

Mapping the Modern Attack Surface: Fintech's Evolving Risk Frontier - Erika Dean - CSP #212

18

Maximizing Cyber Liability Insurance: Risk, Relationships & Renewal Strategies - Mandy Andress - CSP #211

19

Breach by the Dozen: Incident Response Lessons from the Field - Mike Miller - CSP #210

20

AI Governance: Navigating Risks, Frameworks, and the Future - Rock Lambros - CSP #209

21

Privacy Under Siege: Navigating Data Theft and the BadBox Threat - Gavin Reid - CSP #208

22

Cloud Security in Higher Education: Balancing Trust and Risk - Sheena Thomas - CSP #207

23

Cybersecurity in the Cloud: Lessons for Businesses and Beyond - Melina Scotto - CSP #206

24

Cloud Security for SMBs: Strategies, Risks, and Resources - Adam John - CSP #205

25

Cloud Security at Risk: Tackling Misconfigurations Head-On - Nadia Mazzarolo - CSP #204

26

Cloud Security: Lessons Learned and Applied to Emerging Tech - Bertrum Carroll - CSP #203

27

Identity Challenges in Manufacturing - Tammy Klotz - CSP #202

28

Identity Security: Navigating the New Normal with Dr. Sean Murphy - Sean Murphy - CSP #201

29

Identity Security Training: How important is it? - Eric Belardo - CSP #200

30

Have you ever had a pen tester own your network? - Julian Austin - CSP #199

31

How important is your relationship with your tool vendors? - Jacob Lorz - CSP #198

32

What level of tool rationalization does your company do and why? - LaLisha Hurt - CSP #197

33

Have you consider your team's cognitive biases when selecting tools? - Dustin Sachs - CSP #196

34

Tokyo DriftSec: Who is going First? Who is going Smooth? - Lisa Landau - CSP #195

35

What are your pet peeves when it comes to tool selection? - Timothy Ball - CSP #194

36

Tried and True. Going back to basics with Incident Response - Levone Campbell - CSP #193

37

The vCISO's role in Incident Response Accountability - William Klusovsky - CSP #192

38

CISO & Legal: Partnerships Needed - Joe Sullivan - CSP #191

39

Todd's Moving On after 185+ Episodes - Future CISO Vision - Todd Fitzgerald - CSP #190

40

Vulnerability Management: Tips and Techniques - John Kellerhals - CSP #189

41

Are You Vulnerable to Deep Fakes? Controlling the Risk - Paul Neff - CSP #188

42

Focus, Breadth, or Depth: Reduce Vulnerabilities with Less $ - Julian Mihai - CSP #187

43

No One Succeeds Alone! Why You Must Have an Informal Network - Gene Scriven - CSP #186

44

Driving the Business of Infosec Through the GRC Program - Greg Bee - CSP #185

45

Evolving from Security to Trust, more than Just Compliance - Mike Towers - CSP #184

46

CISO Risk Reduction: Adopting Emerging Technologies - Timothy McKnight - CSP #183

47

Deep Dive in GRC: Know Your Sources - Jonathan Ruf - CSP #182

48

Governing Cyber Humanely: Leveraging Wellness Techniques - Jothi Dugar - CSP #181

49

CISOs Advising Cybersecurity Companies, Get on Board! - Bob West - CSP #180

50

As We Implement Zero Trust, Let's Not Forget About Metrics - George Finney - CSP #179

51

CISO and the Board: Demonstrating value and relevant metrics - Max Shier - CSP #178

52

Point Vs. Platform: Improving TCO Cost/Benefit - Patrick Benoit - CSP #177

53

Data Governance is Critical to Info Security and Privacy - Michael Redmond - CSP #176

54

The Riddle of Data Governance - Steven Fox - CSP #175

55

That Data Sprawl is Here! What Should We Do About it? - Nick Ritter - CSP #174

56

Why CISO's Fail: Some Practical Lessons for the Future - Barak Engel - CSP #173

57

Air Gapped! The Myth of Securing OT - Thomas Johnson - CSP #172

58

The Challenges of Managing Security in an IT/OT Environment - John Germain - CSP #171

59

The Importance of OT Security: The Evolving Threat Landscape - Ken Townsend - CSP #170

60

Tips for a Successful Cyber Resilience Program - Olusegun Opeyemi-Ajayi - CSP #169

61

Operational Technology (OT) and the Art of War - Glenn Kapetansky - CSP #168

62

Third-Party Risk Management - BEC Compromises and the Cloud - Michael Swinarski - CSP #167

63

52,000 Suppliers:Third-Party Supply Chain CyberRisk Approach - Cassie Crossley - CSP #166

64

Securing Connections: 3rd Party Risk Mgmt Expert Insights - Charles Spence - CSP #165

65

A Printout on Secure by Design When Utilizing 3rd Parties - Bryan Willett - CSP #164

66

Intelligent Generative AI Handling - Aaron Weismann - CSP #163

67

Responsible Use and Vetting of AI Solutions - Jon Washburn - CSP #162

68

The Business Side of AI - Edward Contreras - CSP #161

69

Generative AI and Corporate Security – Getting it Right - Bill Franks - CSP #160

70

Better CISO Health in the New Year: From Burnout to Balance - Steve Shelton - CSP #159

71

Cloud Security Staffing in a Hybrid World – It Can Be Done! - Larry Lidz - CSP #158

72

You want the CISO Title & Pay? Responsibility Comes Also! - Malcolm Harkins - CSP #157

73

Reimagining Risk in the Emerging Cloud: A GRC Perspective - Solomon Ugah - CSP #156

74

Why Don't We Care About Identity Security? - Don Baham - CSP #155

75

High Consequences Cyber: Make or Break the CISO's Reputation - Andy Jaquith - CSP #154

76

Four Pieces of Transitional Advice: Incoming CISOs - Sean Zadig - CSP #153

77

Is there really an Information Security Jobs Crisis? - Ben Rothke - CSP #152

78

Prioritizing Identity and Getting the Fundamentals Right - Bezawit Sumner - CSP #151

79

Do You Really Want to Be a CISO? - Spencer Mott - CSP #150

80

All in One CISO: There Is Nothing We Can't Do - Jessica Hoffman - CSP #149

81

Building a People-Centric Security Program - Cathy Olsen - CSP #148

82

Veterans Impacting Cybersecurity - David Cross - CSP #147

83

Should We Be Relying on Our Cybersecurity Risk Matrices? - Doug Hubbard - CSP #146

84

OT Is Not IT But Security Can Handle Both - Mea Clift - CSP #145

85

Effective Communication is Critical for CISO Success - Wes Knight - CSP #144

86

Terminology Matters: Changing 'Cybersecurity' to Data Care - Cyndi Gula, Ron Gula - CSP #143

87

NextGen Security Tooling: Investments in Intelligence - Mike Coogan - CSP #142

88

Uber CISO Trial Learnings for CISOs: In the CISO's Own Words - Joe Sullivan - CSP #141

89

Managing CyberRisk in a Mid-Cap Company - Walter Lefmann - CSP #140

90

Collective Defense: The Importance of Partnerships in Cybersecurity - Jamil Farshchi - CSP #139

91

Teams are Built around Key Players Performing Great Functions - Ralston Simmons - CSP #138

92

Championship Results: No Bank Breaking or Boat Rocking! - Steve Hunt - CSP #137

93

Supply Side Security: How to Maintain a Talent Pipeline - Helen Patton - CSP #136

94

Deploying Zero Trust Without Destroying End User Trust - Mike Zachman, Colin Chisholm - CSP #135

95

Security Musings from a Psychotherapeutic Perspective - Mark Eggleston - CSP #134

96

Cyber Risk Governance: The Hype, Hope, & Harsh Reality - John Sapp - CSP #133

97

The Tactics of Being Strategic in Cybersecurity - Jason Elrod - CSP #132

98

Protecting the Nation's Most Sensitive Information & 800-171 Update - Ron Ross - CSP #131

99

The Evolution & Portability of the CISO Role - Sheldon Cuffie - CSP #130

100

Being a CISO in Higher Education - Lorna Koppel - CSP #129

101

Being a CISO in Higher Education - Lorna Koppel - CSP #129

102

Building High Performing Security, RM, & Resilience Teams - Darin Hurd - CSP #128

103

Deliver High Impact Global Security Programs with Low Ego - Rajesh David - CSP #127

104

Security @ Scale: Building Trust, Starting with Cybersecurity - Rob Duhart Jr. - CSP #126

105

The Company's Lawyer is Not Your Lawyer – Legal Self Defense - Larry Dietz - CSP #125

106

Are We Thinking in the Right Way as CISOs? - Sajan Gautam - CSP #124

107

Using Data to Estimate Cyber Risk Financial Implications - Paul Sand - CSP #123

108

SEC Cybersecurity Risk Governance Requirements - Christopher Hetner - CSP #122

109

Cyber-Local: City of Chicago Cybersecurity Mission - Bruce Coffing - CSP #121

110

Establishing and Enrolling Others in a Cybersecurity Vision - Joey Johnson - CSP #120

111

Leadership Lessons Learned and Preparing your CISO Successor - Dave Estlick - CSP #119

112

From Nothing to Something: Overcoming Hurdles - Larry Whiteside Jr - CSP #118

113

20 Years of GRC: What Have we Learned? What is Next? - Michael Rasmussen - CSP #117

114

County Government Cyber: Don't Let the Roadblocks Stop You ft. Michael Dent & Richard Greenberg- CSP #116

115

Connecting with Higher Education: New Talent at the Source - Fred Kwong - CSP #115

116

Security vs. Operations – Balancing the Risk - Ross Leo - CSP #114

117

The Rise of the Chief Product Security Officer - Jason Christman - CSP #113

118

Leading Cybersecurity with Purpose - Nicole Darden Ford - CSP #112

119

Business Ethics and the CISO - Troy Stairwalt - CSP #111

120

100 CISO STORIES Podcasts, What Did we Learn? - CSP #110

121

2023 CISO Cybersecurity Priorities - CSP #109

122

2023 NFL Superbowl: Year-Long Cybersecurity Preparation - Tomás Maldonado - CSP #108

123

The Trends & Future with Cloud (PaaS & IaaS) - Erik Hart - CSP #107

124

Cybersecurity in a 5G World - Timothy Youngblood - CSP #106

125

Dear Auditor: Why is this a high risk finding? Can we talk? - CSP #105

126

Inclusive Leadership for CISOs Now! - CSP #104

127

The Future is Here – Now What? - Patti Titus - CSP #103

128

CISO Soft Skills Will Make or Break You! - Robert Wood - CSP #102

129

Security Top of Mind: Key Learnings from 2022 & Thoughts on 2023 - Ryan Kazanciyan - CSP #101

130

Cybersecurity Myths & Misconceptions: Avoiding the Pitfalls - Eugene Spafford - CSP #100

131

Build a Cybersecurity Vision and Strategy They Can Visualize - Jason Clark - CSP #99

132

What is a vCISO? What Do They Do? Does Having One Make Sense? - Michael Phillips & Matthew DeChant - CSP #98

133

SMB vs Large Infosec: Different Approaches Required! - Dane Sandersen - CSP #97

134

How the CISO can Make the Biggest Impact for the Company - Tim Callahan - CSP #96

135

The Value of Cyber Defense Competitions in Building a Strong SOC - Brian Wickenhauser - CSP #95

136

Surviving and Thriving in the CISO Role for the Long Run - Jim Cameli - CSP #94

137

Approaching Cloud Security from a Cloud-Native Perspective - Josh Dreyfuss - CSP #93

138

NIST Privacy Framework 101 - Dylan Gilbert - CSP #92

139

Cybersecurity Leadership Through Adversity - Marc Varner - CSP #91

140

2022 DBIR Trends: Ransomware, Remote Work, Threat Actors...Oh My! - Chris Novak - CSP #90

141

Are CISOs Experiencing a Mental Health Crisis? - Shamla Naidoo - CSP #89

142

The NIST Cybersecurity Framework Explained - From Its Leader - Matthew Smith - CSP #88

143

Should we be Concerned About Quantum Computing and Cybersecurity Now? - Richard Rushing - CSP #87

144

Are Cryptocurrencies to Blame for the Increase in Ransomware Attacks? - Bob Seeman - CSP #86

145

Cyberinsurance & the CISO: What You Need to Know - Bryan E. Hurd - CSP #85

146

The Positive Power of Community Engagement - Ron Hale - CSP #84

147

The CEO Won't Wear a Security Badge? Try This! - John Ceraolo - CSP #83

148

Have we Forgotten About the Basics? - Benjamin Corll - CSP #82

149

Using MindMaps to Strengthen Cybersecurity - Michael Wilcox - CSP #81

150

How to Talk With Your Lawyer - Mark Daryl Rasch - CSP #80

151

Insider's View of the CISO Search - Joyce Brocaglia - CSP #79

152

Solarwinds From the Inside: The Breach and the Aftermath - Tim Brown - CSP #78

153

Protecting Your Intellectual Property - Michael Boucher - CSP #77

154

Achieving a Competitive Advantage Through Privacy By Design - Ann Cavoukian - CSP #76

155

Attracting Talent Using The Nice Framework - Greg Witte - CSP #75

156

Where Should the CISO Report? Guess Again! - Stephen Fried - CSP #74

157

Educating Senior Management in Cybersecurity - Edward Amoroso - CSP #73

158

Moving From a Techie to a CISO - Shaun Cavanaugh - CSP #72

159

Women in Leadership - Stacy Mill - CSP #71

160

Establishing and Selling The Cost of Cybersecurity - Devon Bryan - CSP #70

161

Deliver Your Board Message with Context and Confidence! - Jason Witty - CSP #69

162

Using Security Metrics as a Shared Goal With Developers - Caroline Wong - CSP #68

163

Keeping Up with the Jones when Your Neighbors Are Bad Actors - Jason Taule - CSP #67

164

Get Ready: 4 Generations Are Returning to The Office! - Caitlin McGaw - CSP #66

165

Control Frameworks Are There For A Reason - Philip Agcaoili - CSP #65

166

Change Controls Are More Necessary Than Ever - Rebecca Herold - CSP #64

167

Determining Cyber Risk Appetite With the Board - Adel Melek - CSP #63

168

CISO Priorities 2022 - CSP #62

169

Why Are We Still Failing at Security? - Wayman Cummings - CSP #61

170

The CISO Six Minute Rule - Renee Stark - CSP #60

171

Lessons Learned from Building an ISAC - Grant Sewell - CSP #59

172

Getting the Board on Board With Security - Richard Clarke - CSP #58

173

Understanding and Preparing for the Next Log4j - Benny Lakunishok - CSP #57

174

A Cost-Effective Approach to Security Risk Management - Jack Jones - CSP #56

175

Creating Security Budgets Where There is No Budget - Kevin Richards - CSP #55

176

When Should You Just Do It Internally or Hire a Consultant? - John Iatonna - CSP #54

177

Designing a Shared Vision with IT and the Business - Scott King - CSP #53

178

Moving to the Cloud? Don't Forget Hardware Security! - Steve Orrin - CSP #52

179

Privacy Hunger Games: Change The Rules - Samantha Thomas - CSP #51

180

Server Room to War Room: Enterprise Incident Response - Dawn-Marie Hutchinson - CSP #50

181

CISO Shortlist: Key Issues to Cover for Todays CISOs - Leon Ravenna - CSP #49

182

The Future Is Now: Model-Driven Security Using Data Science - Jim Routh - CSP #48

183

CISOs Need Training Too! - Candy Alexander - CSP #47

184

No Senior Management Buy-in, No Success - Chris Apgar - CSP #46

185

Skills I Needed to be a First-Time CISO - Richard Kaufmann - CSP #45

186

Which Approach Wins: Compliance or Risk? - Mark Burnette - CSP #44

187

Who Is Your SOC Really For? - Ricardo Lafosse - CSP #43

188

Do You Know where Your Data Is? - William Miaoulis - CSP #42

189

The Nexus of Security, Privacy and Trust - Allison Miller - CSP #41

190

5 Pitfalls Issuing Information Security & Privacy Policies - Charles Cresson Wood - CSP #40

191

45 Minutes and 10,000 Servers Encrypted (NotPetya) - Todd Inskeep - CSP #39

192

Security Awareness That Works! - Steven Lentz - CSP #38

193

Extending Detection and Response to the Cloud - Kathy Wang - CSP #37

194

Security from Scratch: Incident Response on a Shoestring Budget - Sam Monasteri - CSP #36

195

Fiscally Responsible Ways to Train/Build Community - Kevin Novak - CSP #35

196

Communications Before, During and After the Breach - Melanie Ensign - CSP #34

197

The Unpatchable Vulnerability That Is Human Nature - Rachel Tobac - CSP #33

198

Did You Ask For (and Get!) Too Much Security Money! - James Christiansen - CSP #32

199

Practical Considerations for Managing Your MSSP - Johnathan Nguyen-Duy - CSP #31

200

Achieving Security Buy-in: Change Approach, Not Culture - David Nolan - CSP #30

201

Hacking Into Cybersecurity - Kerissa Varma - CSP #29

202

CISO Roundtable: Ransomware Attacks and the True Cost to Business - CSP #28

203

10 Min for a Call? Managing the Security Product Salesperson - Kevin Morrison - CSP #27

204

Developing Secure Agile Code Quickly is Very Achievable! - Glenn Kapetansky - CSP #26

205

Protecting the "Crown Jewels" - Steve Durbin - CSP #25

206

CISOs: Always be a Student, Always be Learning - Phil Attfield - CSP #24

207

CISO Business Enablement: Getting to 'Yes' as a CISO - Dan Lohrmann - CSP #23

208

Want to Elevate CyberSecurity? Relationships Matter! - Mark Weatherford - CSP #22

209

Fixing the Talent Shortage: CyberSecurity Talent Initiative - Alexander Niejelow - CSP #21

210

So You Want to be a Cyber Spy? - Ira Winkler - CSP #20

211

No Insider Cybersecurity Risk? Guess Again! - Dawn Cappelli - CSP #19

212

CISOs Cross the Bridge to the Cloud - Jim Reavis - CSP #18

213

Just Fix It: 5 Critical Elements to Protect the Right Assets - Roland Cloutier - CSP #17

214

Passion for Solving Problems is Key to Security - Will Lin - CSP #16

215

Effective Health Care Security is More Than HIPAA!! - Erik Decker - CSP #15

216

Stop Reporting Useless Security Metrics!! - Edward Marchewka - CSP #14

217

Necessity is the Mother of Security - Tatu Ylonen - CSP #13

218

He Fought the FTC Over a Breach & Won - Michael Daugherty - CSP #12

219

Is There a Magic Security Control List? - Tony Sager - CSP #11

220

Doing Security Before Security Was a Career Path - Petri Kuivala - CSP #10

221

The Colonoscopy of CyberSecurity - Lee Parrish - CSP #9

222

Going All-in on a Career in Security - Mauro Israel - CSP #8

223

Is CyberSecurity ROI Necessary? - Paul Hypki - CSP #7

224

Your Job is to Make CyberSecurity Simple! - Steve Katz - CSP #6

225

...and Other Useless Security Constructs - Robert Bigman - CSP #5

226

Without Building CISO EQ, You May be on Your Own! - Marci McCarthy - CSP #4

227

Doing Privacy Right vs. Doing Privacy Rights - Valerie Lyons - CSP #3

228

Sled Security: Pandemics, Policies, & Penny-Pinching - Ari Schwartz - CSP #2

229

Telling Scary Stories to the Board? Stop. Here's Why. – Mischel Kwon - CSP #1