All Episodes
CISO Stories Podcast (Audio) — 227 episodes
Cloud Security Meets AI: What CISOs Need to Govern Before They Scale - Brent Neal - CSP #226
Critical Infrastructure: The Risk Hiding in Plain Sight - Jason Manar - CSP #225
IAM for MSSPs: The Hidden Risk of Blind Trust - Dustin Sachs - CSP #224
Cloud Security: The AI Effect & How to Proceed - Richard Marcus - CSP #223
From Alerts to Action: Making Public–Private Threat Intel Actually Useful - Ian Washburn - CSP #222
Beyond Vendor Risk: Real-Time GRC, AI, and Protecting App User Data - Jadee Hanson - CSP #221
Keys Without People — John Heasman on Cleaning Up Non-Human Access - John Heasman - CSP #220
Agents at the Door: Vetting Non-Human Identities in External IAM - Rakesh Soni - CSP #219
ATT&CK → ATLAS: A CISO's Blueprint for AI Governance - Sandy Dunn - CSP #218
Security Awareness Through Trust and Influence - Jennifer Selby Long - CSP #217
OT on the Frontlines: Threat Intelligence You Can't Ignore - Dawn Cappelli - CSP #216
Reimagining Security Operations: SOC as a Service and the Role of AI - Kevin Nikkhoo - CSP #215
From Diagram to Cloud: Rethinking Cloud Security in an Age of Uncertainty - Yogita Parulekar - CSP #214
Empowering Developers: Fostering a Culture of Security in AppSec - Danielle Ruderman - CSP #213
Mapping the Modern Attack Surface: Fintech's Evolving Risk Frontier - Erika Dean - CSP #212
Maximizing Cyber Liability Insurance: Risk, Relationships & Renewal Strategies - Mandy Andress - CSP #211
Breach by the Dozen: Incident Response Lessons from the Field - Mike Miller - CSP #210
AI Governance: Navigating Risks, Frameworks, and the Future - Rock Lambros - CSP #209
Privacy Under Siege: Navigating Data Theft and the BadBox Threat - Gavin Reid - CSP #208
Cloud Security in Higher Education: Balancing Trust and Risk - Sheena Thomas - CSP #207
Cybersecurity in the Cloud: Lessons for Businesses and Beyond - Melina Scotto - CSP #206
Cloud Security for SMBs: Strategies, Risks, and Resources - Adam John - CSP #205
Cloud Security at Risk: Tackling Misconfigurations Head-On - Nadia Mazzarolo - CSP #204
Cloud Security: Lessons Learned and Applied to Emerging Tech - Bertrum Carroll - CSP #203
Identity Challenges in Manufacturing - Tammy Klotz - CSP #202
Identity Security: Navigating the New Normal with Dr. Sean Murphy - Sean Murphy - CSP #201
Identity Security Training: How important is it? - Eric Belardo - CSP #200
Have you ever had a pen tester own your network? - Julian Austin - CSP #199
How important is your relationship with your tool vendors? - Jacob Lorz - CSP #198
What level of tool rationalization does your company do and why? - LaLisha Hurt - CSP #197
Have you consider your team's cognitive biases when selecting tools? - Dustin Sachs - CSP #196
Tokyo DriftSec: Who is going First? Who is going Smooth? - Lisa Landau - CSP #195
What are your pet peeves when it comes to tool selection? - Timothy Ball - CSP #194
Tried and True. Going back to basics with Incident Response - Levone Campbell - CSP #193
The vCISO's role in Incident Response Accountability - William Klusovsky - CSP #192
CISO & Legal: Partnerships Needed - Joe Sullivan - CSP #191
Todd's Moving On after 185+ Episodes - Future CISO Vision - Todd Fitzgerald - CSP #190
Vulnerability Management: Tips and Techniques - John Kellerhals - CSP #189
Are You Vulnerable to Deep Fakes? Controlling the Risk - Paul Neff - CSP #188
Focus, Breadth, or Depth: Reduce Vulnerabilities with Less $ - Julian Mihai - CSP #187
No One Succeeds Alone! Why You Must Have an Informal Network - Gene Scriven - CSP #186
Driving the Business of Infosec Through the GRC Program - Greg Bee - CSP #185
Evolving from Security to Trust, more than Just Compliance - Mike Towers - CSP #184
CISO Risk Reduction: Adopting Emerging Technologies - Timothy McKnight - CSP #183
Deep Dive in GRC: Know Your Sources - Jonathan Ruf - CSP #182
Governing Cyber Humanely: Leveraging Wellness Techniques - Jothi Dugar - CSP #181
CISOs Advising Cybersecurity Companies, Get on Board! - Bob West - CSP #180
As We Implement Zero Trust, Let's Not Forget About Metrics - George Finney - CSP #179
CISO and the Board: Demonstrating value and relevant metrics - Max Shier - CSP #178
Point Vs. Platform: Improving TCO Cost/Benefit - Patrick Benoit - CSP #177
Data Governance is Critical to Info Security and Privacy - Michael Redmond - CSP #176
The Riddle of Data Governance - Steven Fox - CSP #175
That Data Sprawl is Here! What Should We Do About it? - Nick Ritter - CSP #174
Why CISO's Fail: Some Practical Lessons for the Future - Barak Engel - CSP #173
Air Gapped! The Myth of Securing OT - Thomas Johnson - CSP #172
The Challenges of Managing Security in an IT/OT Environment - John Germain - CSP #171
The Importance of OT Security: The Evolving Threat Landscape - Ken Townsend - CSP #170
Tips for a Successful Cyber Resilience Program - Olusegun Opeyemi-Ajayi - CSP #169
Operational Technology (OT) and the Art of War - Glenn Kapetansky - CSP #168
Third-Party Risk Management - BEC Compromises and the Cloud - Michael Swinarski - CSP #167
52,000 Suppliers:Third-Party Supply Chain CyberRisk Approach - Cassie Crossley - CSP #166
Securing Connections: 3rd Party Risk Mgmt Expert Insights - Charles Spence - CSP #165
A Printout on Secure by Design When Utilizing 3rd Parties - Bryan Willett - CSP #164
Intelligent Generative AI Handling - Aaron Weismann - CSP #163
Responsible Use and Vetting of AI Solutions - Jon Washburn - CSP #162
The Business Side of AI - Edward Contreras - CSP #161
Generative AI and Corporate Security – Getting it Right - Bill Franks - CSP #160
Better CISO Health in the New Year: From Burnout to Balance - Steve Shelton - CSP #159
Cloud Security Staffing in a Hybrid World – It Can Be Done! - Larry Lidz - CSP #158
You want the CISO Title & Pay? Responsibility Comes Also! - Malcolm Harkins - CSP #157
Reimagining Risk in the Emerging Cloud: A GRC Perspective - Solomon Ugah - CSP #156
Why Don't We Care About Identity Security? - Don Baham - CSP #155
High Consequences Cyber: Make or Break the CISO's Reputation - Andy Jaquith - CSP #154
Four Pieces of Transitional Advice: Incoming CISOs - Sean Zadig - CSP #153
Is there really an Information Security Jobs Crisis? - Ben Rothke - CSP #152
Prioritizing Identity and Getting the Fundamentals Right - Bezawit Sumner - CSP #151
Do You Really Want to Be a CISO? - Spencer Mott - CSP #150
All in One CISO: There Is Nothing We Can't Do - Jessica Hoffman - CSP #149
Building a People-Centric Security Program - Cathy Olsen - CSP #148
Veterans Impacting Cybersecurity - David Cross - CSP #147
Should We Be Relying on Our Cybersecurity Risk Matrices? - Doug Hubbard - CSP #146
OT Is Not IT But Security Can Handle Both - Mea Clift - CSP #145
Effective Communication is Critical for CISO Success - Wes Knight - CSP #144
Terminology Matters: Changing 'Cybersecurity' to Data Care - Cyndi Gula, Ron Gula - CSP #143
NextGen Security Tooling: Investments in Intelligence - Mike Coogan - CSP #142
Uber CISO Trial Learnings for CISOs: In the CISO's Own Words - Joe Sullivan - CSP #141
Managing CyberRisk in a Mid-Cap Company - Walter Lefmann - CSP #140
Collective Defense: The Importance of Partnerships in Cybersecurity - Jamil Farshchi - CSP #139
Teams are Built around Key Players Performing Great Functions - Ralston Simmons - CSP #138
Championship Results: No Bank Breaking or Boat Rocking! - Steve Hunt - CSP #137
Supply Side Security: How to Maintain a Talent Pipeline - Helen Patton - CSP #136
Deploying Zero Trust Without Destroying End User Trust - Mike Zachman, Colin Chisholm - CSP #135
Security Musings from a Psychotherapeutic Perspective - Mark Eggleston - CSP #134
Cyber Risk Governance: The Hype, Hope, & Harsh Reality - John Sapp - CSP #133
The Tactics of Being Strategic in Cybersecurity - Jason Elrod - CSP #132
Protecting the Nation's Most Sensitive Information & 800-171 Update - Ron Ross - CSP #131
The Evolution & Portability of the CISO Role - Sheldon Cuffie - CSP #130
Being a CISO in Higher Education - Lorna Koppel - CSP #129
Being a CISO in Higher Education - Lorna Koppel - CSP #129
Building High Performing Security, RM, & Resilience Teams - Darin Hurd - CSP #128
Deliver High Impact Global Security Programs with Low Ego - Rajesh David - CSP #127
Security @ Scale: Building Trust, Starting with Cybersecurity - Rob Duhart Jr. - CSP #126
The Company's Lawyer is Not Your Lawyer – Legal Self Defense - Larry Dietz - CSP #125
Are We Thinking in the Right Way as CISOs? - Sajan Gautam - CSP #124
Using Data to Estimate Cyber Risk Financial Implications - Paul Sand - CSP #123
SEC Cybersecurity Risk Governance Requirements - Christopher Hetner - CSP #122
Cyber-Local: City of Chicago Cybersecurity Mission - Bruce Coffing - CSP #121
Establishing and Enrolling Others in a Cybersecurity Vision - Joey Johnson - CSP #120
Leadership Lessons Learned and Preparing your CISO Successor - Dave Estlick - CSP #119
From Nothing to Something: Overcoming Hurdles - Larry Whiteside Jr - CSP #118
20 Years of GRC: What Have we Learned? What is Next? - Michael Rasmussen - CSP #117
County Government Cyber: Don't Let the Roadblocks Stop You ft. Michael Dent & Richard Greenberg- CSP #116
Connecting with Higher Education: New Talent at the Source - Fred Kwong - CSP #115
Security vs. Operations – Balancing the Risk - Ross Leo - CSP #114
The Rise of the Chief Product Security Officer - Jason Christman - CSP #113
Leading Cybersecurity with Purpose - Nicole Darden Ford - CSP #112
Business Ethics and the CISO - Troy Stairwalt - CSP #111
100 CISO STORIES Podcasts, What Did we Learn? - CSP #110
2023 CISO Cybersecurity Priorities - CSP #109
2023 NFL Superbowl: Year-Long Cybersecurity Preparation - Tomás Maldonado - CSP #108
The Trends & Future with Cloud (PaaS & IaaS) - Erik Hart - CSP #107
Cybersecurity in a 5G World - Timothy Youngblood - CSP #106
Dear Auditor: Why is this a high risk finding? Can we talk? - CSP #105
Inclusive Leadership for CISOs Now! - CSP #104
The Future is Here – Now What? - Patti Titus - CSP #103
CISO Soft Skills Will Make or Break You! - Robert Wood - CSP #102
Security Top of Mind: Key Learnings from 2022 & Thoughts on 2023 - Ryan Kazanciyan - CSP #101
Cybersecurity Myths & Misconceptions: Avoiding the Pitfalls - Eugene Spafford - CSP #100
Build a Cybersecurity Vision and Strategy They Can Visualize - Jason Clark - CSP #99
What is a vCISO? What Do They Do? Does Having One Make Sense? - Michael Phillips & Matthew DeChant - CSP #98
SMB vs Large Infosec: Different Approaches Required! - Dane Sandersen - CSP #97
How the CISO can Make the Biggest Impact for the Company - Tim Callahan - CSP #96
The Value of Cyber Defense Competitions in Building a Strong SOC - Brian Wickenhauser - CSP #95
Surviving and Thriving in the CISO Role for the Long Run - Jim Cameli - CSP #94
Approaching Cloud Security from a Cloud-Native Perspective - Josh Dreyfuss - CSP #93
NIST Privacy Framework 101 - Dylan Gilbert - CSP #92
Cybersecurity Leadership Through Adversity - Marc Varner - CSP #91
2022 DBIR Trends: Ransomware, Remote Work, Threat Actors...Oh My! - Chris Novak - CSP #90
Are CISOs Experiencing a Mental Health Crisis? - Shamla Naidoo - CSP #89
The NIST Cybersecurity Framework Explained - From Its Leader - Matthew Smith - CSP #88
Should we be Concerned About Quantum Computing and Cybersecurity Now? - Richard Rushing - CSP #87
Are Cryptocurrencies to Blame for the Increase in Ransomware Attacks? - Bob Seeman - CSP #86
Cyberinsurance & the CISO: What You Need to Know - Bryan E. Hurd - CSP #85
The Positive Power of Community Engagement - Ron Hale - CSP #84
The CEO Won't Wear a Security Badge? Try This! - John Ceraolo - CSP #83
Have we Forgotten About the Basics? - Benjamin Corll - CSP #82
Using MindMaps to Strengthen Cybersecurity - Michael Wilcox - CSP #81
How to Talk With Your Lawyer - Mark Daryl Rasch - CSP #80
Insider's View of the CISO Search - Joyce Brocaglia - CSP #79
Solarwinds From the Inside: The Breach and the Aftermath - Tim Brown - CSP #78
Protecting Your Intellectual Property - Michael Boucher - CSP #77
Achieving a Competitive Advantage Through Privacy By Design - Ann Cavoukian - CSP #76
Attracting Talent Using The Nice Framework - Greg Witte - CSP #75
Where Should the CISO Report? Guess Again! - Stephen Fried - CSP #74
Educating Senior Management in Cybersecurity - Edward Amoroso - CSP #73
Moving From a Techie to a CISO - Shaun Cavanaugh - CSP #72
Women in Leadership - Stacy Mill - CSP #71
Establishing and Selling The Cost of Cybersecurity - Devon Bryan - CSP #70
Deliver Your Board Message with Context and Confidence! - Jason Witty - CSP #69
Using Security Metrics as a Shared Goal With Developers - Caroline Wong - CSP #68
Keeping Up with the Jones when Your Neighbors Are Bad Actors - Jason Taule - CSP #67
Get Ready: 4 Generations Are Returning to The Office! - Caitlin McGaw - CSP #66
Control Frameworks Are There For A Reason - Philip Agcaoili - CSP #65
Change Controls Are More Necessary Than Ever - Rebecca Herold - CSP #64
Determining Cyber Risk Appetite With the Board - Adel Melek - CSP #63
CISO Priorities 2022 - CSP #62
Why Are We Still Failing at Security? - Wayman Cummings - CSP #61
The CISO Six Minute Rule - Renee Stark - CSP #60
Lessons Learned from Building an ISAC - Grant Sewell - CSP #59
Getting the Board on Board With Security - Richard Clarke - CSP #58
Understanding and Preparing for the Next Log4j - Benny Lakunishok - CSP #57
A Cost-Effective Approach to Security Risk Management - Jack Jones - CSP #56
Creating Security Budgets Where There is No Budget - Kevin Richards - CSP #55
When Should You Just Do It Internally or Hire a Consultant? - John Iatonna - CSP #54
Designing a Shared Vision with IT and the Business - Scott King - CSP #53
Moving to the Cloud? Don't Forget Hardware Security! - Steve Orrin - CSP #52
Privacy Hunger Games: Change The Rules - Samantha Thomas - CSP #51
Server Room to War Room: Enterprise Incident Response - Dawn-Marie Hutchinson - CSP #50
CISO Shortlist: Key Issues to Cover for Todays CISOs - Leon Ravenna - CSP #49
The Future Is Now: Model-Driven Security Using Data Science - Jim Routh - CSP #48
CISOs Need Training Too! - Candy Alexander - CSP #47
No Senior Management Buy-in, No Success - Chris Apgar - CSP #46
Skills I Needed to be a First-Time CISO - Richard Kaufmann - CSP #45
Which Approach Wins: Compliance or Risk? - Mark Burnette - CSP #44
Who Is Your SOC Really For? - Ricardo Lafosse - CSP #43
Do You Know where Your Data Is? - William Miaoulis - CSP #42
The Nexus of Security, Privacy and Trust - Allison Miller - CSP #41
5 Pitfalls Issuing Information Security & Privacy Policies - Charles Cresson Wood - CSP #40
45 Minutes and 10,000 Servers Encrypted (NotPetya) - Todd Inskeep - CSP #39
Security Awareness That Works! - Steven Lentz - CSP #38
Extending Detection and Response to the Cloud - Kathy Wang - CSP #37
Security from Scratch: Incident Response on a Shoestring Budget - Sam Monasteri - CSP #36
Fiscally Responsible Ways to Train/Build Community - Kevin Novak - CSP #35
Communications Before, During and After the Breach - Melanie Ensign - CSP #34
The Unpatchable Vulnerability That Is Human Nature - Rachel Tobac - CSP #33
Did You Ask For (and Get!) Too Much Security Money! - James Christiansen - CSP #32
Practical Considerations for Managing Your MSSP - Johnathan Nguyen-Duy - CSP #31
Achieving Security Buy-in: Change Approach, Not Culture - David Nolan - CSP #30
Hacking Into Cybersecurity - Kerissa Varma - CSP #29
CISO Roundtable: Ransomware Attacks and the True Cost to Business - CSP #28
10 Min for a Call? Managing the Security Product Salesperson - Kevin Morrison - CSP #27
Developing Secure Agile Code Quickly is Very Achievable! - Glenn Kapetansky - CSP #26
Protecting the "Crown Jewels" - Steve Durbin - CSP #25
CISOs: Always be a Student, Always be Learning - Phil Attfield - CSP #24
CISO Business Enablement: Getting to 'Yes' as a CISO - Dan Lohrmann - CSP #23
Want to Elevate CyberSecurity? Relationships Matter! - Mark Weatherford - CSP #22
Fixing the Talent Shortage: CyberSecurity Talent Initiative - Alexander Niejelow - CSP #21
So You Want to be a Cyber Spy? - Ira Winkler - CSP #20
No Insider Cybersecurity Risk? Guess Again! - Dawn Cappelli - CSP #19
CISOs Cross the Bridge to the Cloud - Jim Reavis - CSP #18
Just Fix It: 5 Critical Elements to Protect the Right Assets - Roland Cloutier - CSP #17
Passion for Solving Problems is Key to Security - Will Lin - CSP #16
Effective Health Care Security is More Than HIPAA!! - Erik Decker - CSP #15
Stop Reporting Useless Security Metrics!! - Edward Marchewka - CSP #14
Necessity is the Mother of Security - Tatu Ylonen - CSP #13
He Fought the FTC Over a Breach & Won - Michael Daugherty - CSP #12
Is There a Magic Security Control List? - Tony Sager - CSP #11
Doing Security Before Security Was a Career Path - Petri Kuivala - CSP #10
The Colonoscopy of CyberSecurity - Lee Parrish - CSP #9
Going All-in on a Career in Security - Mauro Israel - CSP #8
Is CyberSecurity ROI Necessary? - Paul Hypki - CSP #7
Your Job is to Make CyberSecurity Simple! - Steve Katz - CSP #6
...and Other Useless Security Constructs - Robert Bigman - CSP #5
Without Building CISO EQ, You May be on Your Own! - Marci McCarthy - CSP #4
Doing Privacy Right vs. Doing Privacy Rights - Valerie Lyons - CSP #3
Sled Security: Pandemics, Policies, & Penny-Pinching - Ari Schwartz - CSP #2
Telling Scary Stories to the Board? Stop. Here's Why. – Mischel Kwon - CSP #1