Defense in Depth cover art

All Episodes

Defense in Depth — 375 episodes

#
Title
1

Building Resilience for Microsoft 365

2

Recommendations to Reboot the Security Vendor Pitch

3

Market Confusion Is Responsible for the Biggest Gaps in Cybersecurity

4

Will AI Replace Detection Roles in Cybersecurity?

5

What Makes a Good AI Security Deployment?

6

The Office Politics of Remediation

7

Why is Preventative Security So Difficult?

8

Identity and Access Management (IAM) in an Agentic AI World

9

Protecting AI Agents in O365 and Google Workspace

10

Humans Are Bottleneck in a Machine-Speed World

11

Even With All These Security Vendors We Still Have Glaring Gaps

12

Is the "Attackers Only Need to Be Right Once" a Misnomer?

13

What It Takes To Be Successful in Cyber Media

14

CISOs Buy For Selfish and Politically Risk-Averse Reasons (Not Because Your Product is the Best)

15

Has Cybersecurity Become a Cult?

16

What Does the Next Generation of Cloud Security Look Like?

17

The Dangers of Picking the Wrong Vendor

18

Why Cyber Startups Need CISO Advisors

19

Breaking the Reactive Cycle of Cybersecurity

20

How Do You Know If Your Backups Will Survive a Ransomware Attack?

21

What Makes a Successful Security Vendor Demo?

22

Should You Use Native or 3rd Party Cloud Management Tools?

23

How Should We Measure the Performance of a CISO?

24

How to Be Less Busy and More Effective in Cyber

25

How to Engage With a CISO When They Express Interest

26

Who is Responsible for the Conflict Between Security and Developers?

27

Are Your Security Tools Creating More Work for Your Team?

28

Why Overpromising is a Dangerous Sales Tactic

29

Should You Phish Your Employees or Not?

30

How Much Autonomy Should You Give AI Agents in Your SOC?

31

Cybersecurity's Broken Hiring Process

32

Simple Security Solutions That Deliver a Big Impact

33

When Cybersecurity Marketing Fails to Reach the Buyer

34

How Best to Prepare Your Data for Your Tools

35

Don't Try to Win with Technical Expertise. Win by Partnering.

36

What Makes a Successful CISO?

37

How Should CISOs Talk to the Business

38

How Much Cyber Risk Should a CISO Own?

39

How To Tell When a Vendor is Selling AI Snake Oil

40

In the Age of Identity, is Network Security Dead?

41

How to Manage Configuration Drift

42

Is Least Privilege Dead?

43

How Do We Measure Our Defenses Against Social Engineering Attacks?

44

Sales Follow Up Sequences: What Works Best in Cyber?

45

What Soft Skills Do You Need in Cyber?

46

What is the Visibility That Security Teams Need?

47

Data Governance in the Age of AI

48

How Can Security Vendors Better Stand Out?

49

What New Risks Does AI Introduce?

50

The Pattern of Early Adoption of Security Tools

51

How Are You Managing the Flow of AI Data

52

How to Deal with Last Minute Compliance Requirements

53

Do You Have a Functional Policy or Did You Just Write One?

54

Where are We Struggling with Zero Trust

55

Cybersecurity Has a Prioritization Problem

56

How Can AI Provide Useful Guidance from Fragmented Security Data?

57

Why Salespeople's Knowledge of Cybersecurity Is Critical for the Ecosystem

58

What Are the Cybersecurity Trends We Need To Follow?

59

Is It Even Possible to Fast-Track Your Way Into Cybersecurity?

60

What's the Most Efficient Way to Rate Third Party Vendors?

61

Don't Ask "Can" We Secure It, But "How" Can We Secure It

62

Has the Shared Security Model for SaaS Shifted?

63

Improving the Efficiency of Your Threat Intelligence

64

Why Cybersecurity Professionals Lie on Their Resumes

65

What Should Be in a CISO Job Description?

66

The CISO's Job Is Impossible

67

Can You Have a Secure Software Environment Without Traditional Vulnerability Management?

68

How Much Should Salespeople Know About Their Product?

69

Why Are We Still Struggling to Fix Application Security?

70

What Can Someone with No Experience Do in Cybersecurity?

71

Are New Gartner-Created Categories/Acronyms Helping or Hurting the Cybersecurity Industry?

72

Can AI improve Third-Party Risk Management (TPRM)

73

Cybersecurity Is NOT an Entry-Level Position

74

Hey Vendors, What Problem Is Your Product Solving?

75

We've Been Fooled. There Is No Talent Shortage.

76

Is There an Increasing Consolidation of Vendors in the SOC?

77

Are CISOs Struggling to Get Respect?

78

Is Platformization Vs Best-of-Breed a False Dichotomy?

79

Protecting Your Backups from Ransomware

80

Can a Security Program Ever Reach Maintenance Mode?

81

The Hardest Problems in Security Aren't "Security Problems"

82

If and When Should a CISO Have a Long Term Security Plan?

83

Do We Want CISOs Dictating How Salespeople Should Engage?

84

Is AI Benefiting Attackers or Defenders?

85

CISOs DO Own the Risk

86

How Can We Fix Alert Fatigue?

87

Vulnerability Management ≠ Vulnerability Discovery

88

Are Security Awareness Training Platforms Effective?

89

The Argument For More Cybersecurity Startups

90

How Are New SEC Rules Impacting CISOs?

91

Managing the Risk of GenAI Tools

92

Defending Against What Criminals Know About You

93

Will We Ever Go Back From Work From Home?

94

The Lurking Dangers of Neglected Security Tools

95

When You Just Can't Take It Anymore in Cyber

96

Is It Possible to Inject Integrity Into AI?

97

Are Phishing Tests Helping or Hurting Our Security Program?

98

​​Who Is Responsible for Securing SaaS Tools?

99

Hiring Cyber Teenagers with Criminal Records

100

What's Working With Third-Party Risk Management?

101

What Triggers a CISO?

102

Information Security vs. Cybersecurity

103

Should Deny By Default Be the Cornerstone of Zero Trust?

104

What Is a Field CISO?

105

Cybersecurity Is a Communications Problem

106

Do Companies Undergoing a Merger or Acquisition Get Targeted for Attacks?

107

Telling Stories with Security Metrics

108

Securing Identities in the Cloud

109

How AI Is Making Data Security Possible

110

What Makes a Successful CISO?

111

We Want a Solution to Remediate, Not Just Detect Problems

112

Recruiting from the Help Desk

113

How Do We Build a Security Program to Thwart Deepfakes?

114

Where Are Secure Web Gateways Falling Short?

115

Understanding the Zero-Trust Landscape

116

Scaling Least Privilege for the Cloud

117

Should CISOs Be More Empathetic Towards Salespeople?

118

Managing Data Leaks Outside Your Perimeter

119

What Are the Risks of Being a CISO?

120

Onboarding Security Professionals

121

How to Improve Your Relationship With Your Boss

122

Improving the Responsiveness of Your SOC

123

The Demand for Affordable Blue Team Training

124

Why are CISOs Excluded from Executive Leadership?

125

What Is Your SOC's Single Search of Truth?

126

When Is Data an Asset and When Is It a Liability?

127

Tracking Anomalous Behaviors of Legitimate Identities

128

Why Do Cybersecurity Startups Fail?

129

Is "Compliance Doesn't Equal Security" a Pointless Argument?

130

CISOs Responsibilities Before and After an M&A

131

Use Red Teaming To Build, Not Validate, Your Security Program

132

The Do's and Don'ts of Approaching CISOs

133

Doing Third Party Risk Management Right

134

Warning Signs You're About To Be Attacked

135

Do We Have to Fix ALL the Critical Vulnerabilities?

136

Mitigating Generative AI Risks

137

Building a Cyber Strategy for Unknown Unknowns

138

Responsibly Embracing Generative AI

139

People Are the Top Attack Vector (Not the Weakest Link)

140

What's Entry Level in Cybersecurity?

141

New SEC Rules for Cyber Security

142

The Value of RSA, Black Hat, and Mega Cyber Tradeshows

143

Is Remote Work Helping or Hurting Cybersecurity?

144

How to Manage Users' Desires for New Technology

145

Cybersecurity Questions Heard Around the Kitchen Table

146

How to Prime Your Data Lake

147

Getting Ahead Of Your Threat Intelligence Program

148

How Security Leaders Deal with Intense Stress

149

How Do We Influence Secure Behavior?

150

Security Concerns with ChatGPT

151

Create A Pipeline of Cyber Talent

152

Improving Adoption of Least Privileged Access

153

Securing SaaS Applications

154

How Do We Get Better Control of Cloud Data?

155

Finding Your Security Community

156

Let's Write Better Cybersecurity Job Descriptions

157

How Should Security Better Engage with Application Owners?

158

How To Get More People Into Cybersecurity

159

How to Create a Positive Security Culture

160

How Should We Trust Entry Level Employees?

161

How Must Processes Change to Reduce Risk?

162

Reputational Damage from Breaches

163

Do RFPs Work?

164

Successful Cloud Security

165

How Should Security Vendors Engage With CISOs?

166

Gartner Created Product Categories

167

How to Always Make a Business Case for Security

168

Do Breaches Happen Because the Tool Fails, or the Tool Was Poorly Configured?

169

What We Love About Working in Cybersecurity

170

Security That Accounts for Human Fallibility

171

Why You Should Be Your Company's Next CISO

172

How to Become a CISO

173

Can You Build a Security Program on Open Source?

174

Third Party Risk vs. Third Party Trust

175

How Can We Improve the Cyber Sales Cycle?

176

What Leads a Security Program: Risk or Maturity?

177

Limitations of Security Frameworks

178

Why Is There a Cybersecurity Skills Gap?

179

What Can the Cyber Haves Do for the Cyber Have Nots?

180

Securing Unmanaged Assets

181

Ambulance Chasing Security Vendors

182

Do CISOs Have More Stress than Other C-Suite Jobs

183

How Should We Discuss Cyber With the C-Suite?

184

Can You Be a vCISO If You've Never Been a CISO?

185

How Should We Gauge a Company's Cyber Health?

186

Reducing the Attack Surface

187

Do We Need a Marketing Manager for the Security Team?

188

Cybersecurity Budgets

189

How Can We Make Sense of Cybersecurity Titles?

190

Walk a Mile in a Security Recruiter's Shoes

191

Moving Security from a Prevention to a Resilience Strategy

192

How to Engage with Non-Technical Business Leaders

193

Cybersecurity Burnout

194

How to Build a Greenfield Security Program

195

Managing the Onslaught of Files

196

Can You Have Culture Fit and Diversity, or Are They Mutually Exclusive?

197

How to Follow Up With a CISO

198

Roles to Prepare You to Be a CISO

199

Minimizing Damage from a Breach

200

We're All Still Learning Cyber

201

Practical Cybersecurity for IT Professionals

202

Data Protection for Whatever Comes Next

203

What Is Attack Surface Profiling?

204

How Can You Tell If Your Security Program Is Improving?

205

How Can We Improve Recruiting of CISOs and Security Leaders?

206

How Is Our Data Being Weaponized Against Us?

207

Can Security Be a Profit Center?

208

Getting Ahead of the Ongoing Malware Fight

209

Building a Security Awareness Training Program

210

Onboarding Cyber Professionals with No Experience

211

Where's the Trust in Zero Trust?

212

Who Investigates Cyber Solutions?

213

Does the Cybersecurity Industry Suck?

214

Are We Taking Zero Trust Too Far?

215

Is Shift Left Working?

216

Technical vs. Compliance Professionals

217

Why Do So Many Cybersecurity Products Suck?

218

Training for a Cyber Disaster

219

Virtual Patching

220

Start a Cybersecurity Department from Scratch

221

How to Think Like a Cybercrook

222

Building a Data-First Security Program

223

Offensive Security

224

When Vendors Pounce on New CISOs

225

Building a Cybersecurity Culture

226

How to Pitch to a Security Analyst

227

Is Your Data Safer in the Cloud?

228

What Should We Stop Doing in Cybersecurity?

229

DDoS Solutions

230

Making Cybersecurity Faster and More Responsive

231

Promises of Automation

232

When Social Engineering Bypasses Our Cyber Tools

233

How Can We Simplify Security?

234

Convergence of Physical and Digital Security

235

How Do You Measure Cybersecurity Success?

236

How Do We Turn Tables Against Adversaries?

237

Ageism in Cybersecurity

238

Proactive Vulnerability Management

239

Why Is Security Recruiting So Broken?

240

How to Be a Vendor that CISOs Love

241

The "Are We Secure?" Question

242

Ransomware Kill Chain

243

Can Technology Solve Phishing?

244

Convergence of SIEM and SOAR

245

Cybersecurity Is Not Easy to Get Into

246

Preventing Ransomware

247

Managing Lateral Movement

248

First Steps as a CISO

249

How Does Ransomware Enter the Network?

250

What's the Value of Certifications?

251

Measuring the Success of Cloud Security

252

How do I get my first cybersecurity job?

253

Educating the Board About Cybersecurity

254

CISO Recruiting Is Broken

255

Retaining Cyber Talent

256

Salesforce Security

257

Cloud Configuration Fails

258

Starting Pay for Cyber Staff

259

Fear of Automation

260

Hiring Talent with No Security Experience

261

Security Hygiene for Software Development

262

How Much Do You Know About Your Data?

263

Do Startups Need a CISO?

264

Insider Risk

265

What's the Obsession with Zero Trust?

266

Mentoring

267

Securing the Super Bowl and Other Huge Events

268

Cybersecurity Isn't That Difficult

269

Cloud Security Myths

270

What Is Security's Mission?

271

Vendor CISOs

272

How Much Log Data Is Enough?

273

Should Finance or Legal Mentor Cyber?

274

Data Destruction

275

How to Make Cybersecurity More Efficient

276

Does a CISO Need Tech Skills?

277

How Do You Know if You're Good at Security?

278

Building a Security Team

279

Are our Data Protection Strategies Evolving?

280

Should CISOs Be Licensed Professionals?

281

Inherently Vulnerable By Design

282

Imposter Syndrome

283

Why Don't More Companies Take Cybersecurity Seriously?

284

Data Protection and Visibility

285

What's an Entry Level Cybersecurity Job?

286

Securing Digital Transformations

287

Leaked Secrets in Code Repositories

288

Measuring the Success of Your Security Program

289

Privacy Is An Uphill Battle

290

Legal Protection for CISOs

291

XDR: Extended Detection and Response

292

Calling Users Stupid

293

Is College Necessary for a Job in Cybersecurity?

294

When Red Teams Break Down

295

What Cyber Pro Are You Trying to Hire?

296

Junior Cyber People

297

Trusting Security Vendor Claims

298

How Vendors Should Approach CISOs

299

Secure Access

300

InfoSec Fatigue

301

Securing a Cloud Migration

302

API Security

303

Shared Threat Intelligence

304

Drudgery of Cybercrime

305

Security Budgets

306

Role of the BISO

307

Shared Accounts

308

Bug Bounties

309

Data Classification

310

Prevention vs. Detection and Containment

311

Asset Valuation

312

DevSecOps

313

Fix Security Problems with What You've Got

314

Should Risk Lead GRC?

315

Responsible Disclosure

316

Internet of Things

317

Is Governance the Most Important Part of GRC?

318

Who Should the CISO Report To?

319

Hybrid Cloud

320

CISO Tenure

321

Toxic Security Teams

322

Personality Tests in the Workplace

323

Lack of Diversity in Cybersecurity

324

When Are CISOs Responsible for Breaches?

325

Post Breach Desperation and Salary Negotiations

326

Presenting to the Board

327

The Iran Cybersecurity Threat

328

Building a Fully Remote Security Team

329

Account Takeover

330

UX in Cybersecurity

331

InfoSec Trends for 2020

332

Cybersecurity Readiness as Hiring Criteria

333

Cybersecurity and the Media

334

The Cloud and Shared Security

335

Is Product Security Improving?

336

Best Starting Security Framework

337

Cyber Defense Matrix

338

User-Centric Security

339

Securing the New Internet

340

Resiliency

341

Ransomware

342

Top CISO Communication Issues

343

Cybersecurity Excuses

344

Employee Hacking

345

100% Security

346

Proactive Security

347

ATT&CK Matrix

348

Hacker Culture

349

Bad Best Practices

350

Cyber Harassment

351

CISO Series One Year Review

352

Economics of Data

353

Tool Consolidation

354

Camry Security

355

Amplifying Your Security Posture

356

ERP Security

357

Managing Obsolete (Yet Business Critical) Systems

358

Cybersecurity Hiring

359

How CISOs Discover New Solutions

360

Is the Cybersecurity Industry Solving Our Problems?

361

Vulnerability Management

362

Privileged Access Management

363

Machine Learning Failures

364

Software Fixing Hardware Problems

365

Tools for Managing 3rd Party Risk

366

CISO Burnout

367

RSA 2019: Success or Failure?

368

Security IS the Business

369

Threat Intelligence

370

Secure Controls Framework

371

Insider Threats

372

Building an Information Security Council

373

Privacy

374

Security Metrics

375

Welcome to Defense in Depth