CISO Series Podcast
Formerly named CISO/Security Vendor Relationship Podcast. Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.

All links and images for this episode can be found on CISO Series

Managing my own risk is tough enough, but now I have to worry about my partners' risk and their partners' risk? I don't even know what's easier to manage: the risk profile of all my third parties or all the exclusions I've got to open up to let third parties into my system.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our sponsored guest is Bruce Potter (@gdead), CISO, Expel.

Thanks to our podcast sponsor, Expel

Expel

Expel offers companies of all shapes and sizes the capabilities of a modern Security Operations Center without the cost and headache of managing one.

In this episode:

  • What's easier to manage, 3rd party risk profiles or exclusions?
  • Do you need a Git repository to apply for a job? What else?
  • What's in your happy-grab-bag for hybrid work environments?
  • Is there anything new to say about ransomware strategy?  
Direct download: CISO_Vendor_8-03-21_FINAL.mp3
Category:podcast -- posted at: 2:22pm PDT

All links and images for this episode can be found on CISO Series

If I'm going to be riding my team really hard, how much charisma will I need to keep the team frightened so they stay motivated, yet don't want to leave?

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Jason Fruge (@jasonfruge), CISO, Rent-a-Center.

Thanks to our podcast sponsor, Expel

Thanks to our sponsor, Expel

Expel offers companies of all shapes and sizes the capabilities of a modern Security Operations Center without the cost and headache of managing one.

In this episode

  • CISO's second job: applying lessons learned from the first one
  • Experts weigh in on what to do when a breach drops malware on you
  • How to motivate staff to push themselves beyond initial expectations?
  • What level of autonomy do you give your staff to make purchase decisions?
Direct download: CISO_Vendor_07-27-21_Final.mp3
Category:podcast -- posted at: 3:00am PDT

All links and images for this episode can be found on CISO Series

Great, you just purchased the cloud. Are you a little confused as to what you're going to do with it? Not a problem. Let's get you set up right with a world class misconfiguration. That should leave you open to all kinds of breaches.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Johnathan Keith, CISO, Viacom/CBS Streaming.

Thanks to our podcast sponsor, AppOmni

Thanks to our podcast sponsor, AppOmni

AppOmni is building the future of SaaS security. We empower our users to enforce security standards across their SaaS applications, and enable them to remediate in confidence knowing they’re fixing the most important SaaS security issues first. Contact us at www.appomni.com to find out who - and what - has access to your SaaS data.

  • Why do we hear so many stories about poor & misconfigured cloud services?
  • The benefits of Infrastructure as Code (IaC)
  • What makes a vendor meeting worth your time?
  • What's the best way to learn about a company's culture in a job interview?

 

 

Direct download: CISO_Vendor_07-20-21_Final.mp3
Category:podcast -- posted at: 3:00am PDT

All links and images for this episode can be found on CISO Series

We're trying really hard to keep our customers' data safe, but we all know given the number of attacks happening, our number will eventually come up, and we'll lose your data just like every other organization you trusted.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Sandy Dunn (@sub0girl), CISO, Blue Cross of Idaho.

Thanks to our podcast sponsor, Expel

Expel

Expel offers companies of all shapes and sizes the capabilities of a modern Security Operations Center without the cost and headache of managing one.

  • Dissecting Allen Gwynn's "one strike" opinion piece
  • Transitioning cybersec into a mindset for all employees
  • Shifting the risk: buying cyberinsurance instead of tools
  • What's the proper way to behave during a breach?
Direct download: CISO_Vendor_07-13-21_Final.mp3
Category:podcast -- posted at: 3:00am PDT

All links and images for this episode can be found on CISO Series

As good as our virtual bouncers are, they often let in people with what seems to be a valid ID, and then once they're in our nightclub they cause a disruption and we have to kick them out.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our sponsored guest is Sandy Wenzel (@malwaremama), cybersecurity transformation engineer, VMware

Sandy also recommends participating in Pro's vs. Joe's CTF.

Thanks to our podcast sponsor, VMware

VMware

In this episode:

  • How we have become more agile (and how we define agile)
  • Five skills every SOC analyst needs (and how to build them)
  • Lateral movement by threat actors (what have we heard enough of)
  • What are some good assignments to give a cybersecurity intern (and are there better ones?)

 

 

Direct download: CISO_Vendor_07-06-21_Final.mp3
Category:podcast -- posted at: 3:00am PDT