CISO Series Podcast
Formerly named CISO/Security Vendor Relationship Podcast. Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.

All links and images for this episode can be found on CISO Series

It’s extremely hard to tell if a cybersecurity leader is doing a good job. In fact, it’s tough for even them to know. Our best bet is watching for an improvement in the cybersecurity program over time.

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our sponsored guest is Mark Wojtasiak (@markwojtasiak), vice president, research & strategy, Code42 and co-author of “Inside Jobs.”

Thanks to this week’s podcast sponsor, Code42

Thanks to this week’s podcast sponsor, Code42

As organizations gradually and cautiously move out of adapt out of adapt-or-die mode into the post-pandemic era, we can expect a second phase of digital transformation: resilience building. This presents an opportunity for security teams. An opportunity to re-imagine data security. More from Code42.

In this episode:

  • What is your business's biggest frustration when managing cybersecurity?
  • Aaaand...what is your biggest frustration when managing cybersecurity?
  • How do you know when a Security Leader (including yourself) is doing a good job?
  • Would it help if Security hired a marketing manager?

 

 

 

 

Direct download: CISO_Vendor_10-26-21_Final.mp3
Category:podcast -- posted at: 3:00am PDT

Here's an awesome bonus episode of CISO/Security Vendor Relationship Podcast featured as the closing event at Evanta's Global CISO Virtual Executive Summit.

Here's what went down. The day before our recording, three representatives presented their unique and innovative security solutions to a panel of CISOs and the virtual audience in attendance.

The next day, everyone came back to offer up a quick elevator pitch and to be grilled by the CISOs. That's exactly what you get to hear on this bonus episode of CISO/Security Vendor Relationship Podcast.

Thanks to all our sponsors for this bonus episode of the podcast

Kasada

Kasada

Axis Security

Axis Security

Ordr

Ordr

Ten Eleven Ventures

Ten Eleven Ventures

Direct download: CISO_Vendor_10-22-21_Final.mp3
Category:podcast -- posted at: 3:00am PDT

All links and images for this episode can be found on CISO Series

What game should we play where we can trust you to behave fairly, but at the same time see how you could take advantage of us?

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Deneen DiFiore (@deneendifiore), CISO, United Airlines.

Thanks to our podcast sponsor, Code42

Thanks to our podcast sponsor, Code42

As organizations gradually and cautiously move out of adapt out of adapt-or-die mode into the post-pandemic era, we can expect a second phase of digital transformation: resilience building. This presents an opportunity for security teams. An opportunity to re-imagine data security. More from Code42.

In this episode:

  • Does becoming a business-minded security person take time?
  • What does a qualified, entry level candidate have to do to get noticed?
  • Without clear ROI, how does a CISO justify their budget?
  • What game taught you the most about thinking like a hacker?

 

 

Direct download: CISO_Vendor_10-19-21_Final.mp3
Category:podcast -- posted at: 3:00am PDT

All links and images for this episode can be found on CISO Series

Do you really need hundreds of questions to know if you want to work with a vendor? Won’t just two or three well-pointed questions really give you a good idea?

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Our guest is Nick Selby (@fuzztech), CSO, Paxos Trust Company and co-host of Tech Debt Burndown podcast.

Thanks to our podcast sponsor, Kenna Security

Kenna Security

In this episode:

  • How do you suss out security vendors to make sure they're not a risk?
  • How do you battle a typosquatter?
  • What types of preparations do you have in place to know you're well prepared for an incident?
  • How should CISOs and CIOs share cybersecurity ownership?
Direct download: CISO_Vendor_10-12-21_Final.mp3
Category:podcast -- posted at: 3:00am PDT

All links and images for this episode can be found on CISO Series

OK, you showed us our vulnerability. But we really don't want to fix it now. Could we just pay you off to keep quiet, and to buy us some more time to deal with this in a "not so timely" manner?

This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson. Our guest is Sameer Sait (@sameersait), CISO, Amazon - Whole Foods.

Thanks to our podcast sponsor, Code42

Code42

As organizations gradually and cautiously move out of adapt out of adapt-or-die mode into the post-pandemic era, we can expect a second phase of digital transformation: resilience building. This presents an opportunity for security teams. An opportunity to re-imagine data security. More from Code42.

In this episode:

  • What if software developers used academic citations for code acquired from outside sources?
  • What is a reported security vulnerability doesn't get fixed? Where do you go next?
  • What if a 3rd party app developer needs access to a file/print share over the internet?
  • What if you receive a pitch that makes a grandiose statement like "no false positives?" Follow-up or hard pass?

 

Direct download: CISO_Vendor_10-05-21_Final.mp3
Category:podcast -- posted at: 3:00am PDT