The Virtual CISO Podcast cover art

All Episodes

The Virtual CISO Podcast — 161 episodes

#
Title
1

Episode 160: Managing Identity in the Age of AI Agents With Geoffrey Mattson

2

Episode 159: The New Security Stack: Doors, Data, and AI With Jeffrey Friedman

3

Episode 158: AI Is Increasing Your Cyber Risk – Can It Also Reduce It? With Mike Armistead

4

Episode 157: AI Security: Testing, Exploits, and Threat Feeds With Marco Figueroa

5

Episode 156: AI Security: Threat Modeling & Pipeline Evolution with Jason Rebholz

6

Episode 155: Incident Response Testing in Cloud Forward Organizations with Matt Lea

7

Ep 154: How DORA Will Impact US Companies with Dejan Kosutic

8

Ep 153: Inside ISO 42001: The Future of AI Governance with Danny Manimbo

9

EP 152: Granular, Persistent, Zero Trust: The Case for File-Level Security

10

EP 151: Trust, But Verify: How HITRUST is Reshaping Assurance

11

Ep 150: Is OSCAL the Future of Security Documentation (& FedRAMP)?

12

Ep 149: Unlocking the Future: Passkeys and Passwordless Authentication with Anna Pobletts

13

Episode 148: Cloud Detection & Response

14

Episode 147: Why vCISO Engagements Fail

15

Episode 146: Dark Web Monitoring

16

Episode 145: CMMC: The Final Rule

17

Episode 144: TxRAMP or StateRAMP or AZRAMP or FedRAMP? What’s right for your company?

18

Episode 143: Is Decentralized Proof of Security Leveraging Blockchain the future of Cybersecurity?

19

Episode 142: CNAPP - Secure Cloud Apps in a Snap

20

Episode 141: Stopping Business Email Compromise with a Novel Malicious File Reconstruction Approach

21

Episode 140: DIB/CMMC Cybersecurity – Interesting Observations from a Significant Study

22

Episode 139: How adding Crisis Management to your Incident Response Plan can save your bacon?

23

Episode 138: Is Consuming SaaS an Information Security Faustian Bargain? w/ William Eshagh

24

Episode 137: Strategies and Insights w/ Sagi Brody

25

Episode 136: AI Risk Management – Is ISO 42001 the Solution? w/ Ariel Allensworth

26

Episode 135: Can Distributed Ledger Technology Simplify Privacy Compliance? W/ Zenobia Godschalk

27

Episode 134: Understanding TISAX w/ Alexander Häusler

28

Kubernetes Security – Simplified Shauli Rozen, CEO of ARMO

29

Episode 132: Optimize Your SOC 2 - Lessons Learned from the 2023 Benchmark Study w/ Scott Woznicki

30

Episode 131: The New CMCC Proposed Rule w/ Jeff Carden & Warren Hylton

31

Episode 130: Revolutionizing Security Training with Kevin Paige CISO and VP of Product Strategy at Uptycs

32

Episode 129: Empowering Diversity in the Cybersecurity Industry with Larry Whiteside Jr.

33

Episode 128: Understanding the ISO 27001:2022 Update with Andrew Frost and Leigh Ronczka

34

Ep 127: The Future of Security: Unraveling the World of Social Engineering

35

Ep 126: Unlocking AI's Potential: Risks, Optimism & Challenges in the Current Wave of AI Technology

36

Ep: 125 - Understanding the New FTC Safeguards Rule: Key Changes and Requirements Explained

37

An Introduction to AI and its Place in the Work Place with CEO of Private AI Patricia Thaine

38

Ep 123: Navigating IT-OT Dynamics: Cybersecurity, Integration, and Collaboration

39

Ep 122: Navigating New Horizons: CMMC, NIST 800-171 Updates, and Compliance Insights

40

Ep 121: Strategies for Reducing the Cost of Your Cyber Liability Insurance Policy

41

Ep 120: A FedRAMP ATO – The Good, The Bad, and the Ugly

42

Ep 119: What is a Microservice Architecture and how do I secure it?

43

Ep 118: The Simplest Way to Transition from ISO 27001:2013 to ISO 27001:2022

44

Ep 117: Eight Key Takeaways from the RSA 2023 Conference

45

Ep 116: What is an SBOM & Why Are My Customers Suddenly Asking for One?

46

Ep 115: If Your Asset Management Sucks, Your Security Sucks

47

Ep 114: 4 Tactical Steps To Implementing DevSecOps In 2023

48

Ep 113: Should we be in Microsoft 365 GCC, GCC High, or Commercial?

49

Ep 112: When should you move to ISO 27001:2022?

50

Ep 111: How to use the Software Assurance Maturity Model (SAMM) to Build Highly Secure Applications

51

Ep 110: Understanding TISAX (Trusted Information Security Assessment Exchange)

52

Ep 109: Understanding How Cybercriminals Operate Can Protect Your Business

53

Ep 108: Understanding the Legalities Around CUI

54

Ep 107: An AWS Security Guru’s Recommendation for Securing your AWS Infrastructure

55

Ep 106: Strategies to Manage Cybersecurity through an Economic Downturn

56

Ep 105: Solving the Problems of Cloud Native Apps.

57

Ep 104: Is Digital Business Risk Mgt. The Future of ASM

58

Ep 103: The Complexity of Deploying a Secure Application in the Cloud

59

Ep 102: The Intersection of Privacy and Security

60

Ep 101: Most Asked CMMC Questions

61

Ep 100: The Two Audiences For Privacy & How They Drive Data Collection

62

Unpacking Critical Elements of Supply Chain Risk Management

63

Breaking Down the Latest in Software Security Standards & the Impact on SaaS Businesses

64

What You Need to Know about APIs and API Security

65

How to Measure the Value of Information Security

66

Understanding NIST’s Secure Software Development Framework

67

US Gov. Cybersecurity Roadmap: Where it came from and Where is it Going?

68

Confronting the Wild West of Database Security

69

Bridging the Gap Between Cybersecurity and the Business World

70

Legal and Infosec strategies to deal with exploding Cyber Liability Insurance premiums

71

Important Clarifications on CMMC v2 from CMMC Day May 9, 2022

72

The Past, Present and Future of Cybersecurity From the Viewpoint of a Venture Capitalist

73

Understanding Attack Surface Management and How It Applies to Your Cyber Security Strategy

74

The Convergence of Physical & Cyber Security and the Impact to Cyber Security Professionals

75

What CMMC 2 Guidance Means for Managed Service Providers (MSPs)

76

8 Ingredients for Baking Inclusivity into Your Culture

77

Becoming More Efficient w/ a Cloud-Native Approach

78

Use the CSA Cloud Controls to Maximize Your Security & Reduce Your Risk of Breach

79

Ongoing Challenges in CMMC

80

Is Open Source the Future of Endpoint Security

81

The AWS Approach to Provable Security

82

What Does the New ISO 27002 Update Mean for You?

83

CMMC 2.0 & Continuous Compliance w/ Andrea Willis

84

8 Information Security Predictions for 2022

85

Government Security Guidance: How We Got Here

86

How Hardware Hackers Exploit IoT Vulnerabilities w/ Joe Grand

87

Bridging the Gap Between Security & Development Teams w/ Harshil Parikh

88

Why Cloud Is More Secure Than Your Average On-Prem Solution w/ Mark Richman

89

How Configuration Management Makes Security Simple w/ Brian Hajost

90

CMMC 2.0 is Here! Find Out What It Really Means for DIB and Non-DIB USG

91

How Simply Cyber Helps People Pivot to a Cybersecurity Career w/ Gerald Auger

92

Can You Benefit from Attack Surface Management? w/ Steve Ginty

93

Why Continuous Compliance Matters More than Ever w/ Mosi Platt

94

How HIPAA Compliant Email is Revolutionizing Healthcare w/ Hoala Greevy

95

Private Practices: How to Prioritize Privacy in Your Organization w/ Jason Powell

96

Why Information Security Is Key to Business Strategy w/ Chris Dorr

97

Head in the Clouds: Multi-Cloud Security & Governance w/ John Grange

98

Can We Predict Security Threats w/ Machine Learning? w/ Johnna Verry

99

What People Get Wrong About ISO 27001 Compliance

100

Bridging the Gap Between Traditional Compliance & DevOPs w/ Raj Krishnamurthy

101

A Guide for Validating Your Security Process w/ John Verry

102

Governing Cybersecurity: A Process for Becoming Provably Secure & Compliant w/ John Verry

103

The Cybersecurity Executive Order: What You Need to Know w/ Scott Sarris

104

Your Passwords Are Failing You w/Josh Amishav-Zlatin

105

Information Governance w/David Gould

106

DIBCAC & CMMC Audit Prep w/ George Perezdiaz & Caleb Leidy

107

Trust Is a Vulnerability: 5 Steps on the Path to Zero Trust with John Kindervag

108

You Are a Target: Assessing Cybersecurity Risk with Dr. Eric Cole

109

CMMC Assessments Are Here: What You Need to Know with Stacy High-Brinkley

110

Everything You Need to Know About StateRAMP with Leah McGrath

111

How EDR & NDR Help You Make Better Security Decisions with Chris Neyhuis

112

How PreVeil Drive Makes Storing and Sharing Data More Secure with Sanjeev Verma

113

Lessons Learned in Our Initial 27701 Certification Audits

114

Using your ISO 9001 Management System to Simplify CMMC Certification

115

How to Communicate Across Departmental Divides

116

MSPs, MSSPs & Validation: What You Need to Know

117

Why CMMC Is the Most Significant Standard of all Time

118

CMMC Level 1: An Overview

119

Solutions to Security, Compliance, and Technology Challenges in Aerospace

120

CMMC Level 3: What Government Staffing Agencies Need to Know

121

The ISVS: What You Need to Know

122

FedRAMP: What You Need to Know

123

How Data Privacy Standards Affect Your Business

124

Should You Invest in a GRC Tool for Security & Compliance?

125

CMMC Compliance: The Nuances You Should Know

126

GCC High Demystified: What CMMC Compliance Means for DIB Firms

127

What DIB Firms Need to Know About the CMMC Interim Rule

128

The Secrets to Keeping Your SaaS Secure

129

32. How IoT Is Shaping the Future of Cybersecurity

130

31. A Brief History of NIST Guidance

131

30. How to Beat the 6 Most Challenging CMMC L3 Requirements

132

29. How COVID-19 Is Shaping Security’s Future w/Reg Harnish

133

28. Why 800-171 Compliance Isn’t Going Away Any Time Soon w/John Ellis

134

27. How DevOps Took Over (& Why You Should Care) w/Jon Bass

135

26: How to Optimize Your ISMS w/Rich Stever

136

25: CMMC Compliance & Continuous Monitoring Made Simple w/Chris Lank

137

24: Everything You Need to Know About ISO 27001 Audits w/ Ryan Mackie

138

23. Why Security Is So Important for a Growing SaaS w/ Jesse Nash

139

22. CMMC Training & Assessments: Rollout, Certification & Competition w/ Ben Tchoubineh

140

21. CMMC Compliance Doesn’t Have to Be Hard (or Pricey) w/ Sanjeev Verma

141

20. Faster, Better & Cheaper Vendor Due Diligence Reviews w/ Kevin Hermosura

142

19. Why Application Security is a Team Sport and How Your Team Can Win w/ Joe Manico

143

18. IT & Security: How to Do More with Less w/ Jose Ciriaco

144

17. CMMC Certification Audits—Can You Leverage ISO 27001? w/ Thomas Price

145

16. Why Buyers of Security Services Need to Leverage CREST w/ Ian Glover

146

15. The OWASP Top Ten is Great, but is it Enough? w/ Andrew van der Stock

147

14. How Computer Forensics Protects Your Data During Litigation w/ Brian Dykstra

148

13. Why ISO 27701 is the Answer to Privacy Compliance w/ Debbie Zaller

149

12. Disaster Recovery, Business Continuity, and Data Resilience w/ Cosmo Gazzani

150

11. OWASP ASVS: The Go-To Standard for Application Security w/ Daniel Cuthbert

151

10. Exostar and Their Role in Your CMMC Certification w/ Stuart Itkin

152

9. When an SMB Should Implement a SIEM w/ Danielle Russell

153

8. Resilience Guidance and the SCA w/ Tom Garrubba

154

7: Dead CISO's Don't Get Bonuses w/ Dr. Joel Kahn

155

6. The Virtual CIO: What it Is and What it Isn’t w/ Darek Hahn

156

5. Staying Secure in a COVID-19 World w/ John Verry

157

4. True Confessions of a Real Virtual CISO w/ Andrew Farkas

158

3. ISO 27001 vs. SOC 2 – Which Attestation is Right For You? w/ Dan Schroeder

159

2. How to Attract and Retain Cyber Talent w/ Deidre Diamond

160

1. CMMC: What You Need to Know About DoD Cybersecurity Regulation w/ Katie Arrington

161

Welcome to The Virtual CISO Podcast