The Cyber Security Transformation Podcast

Follow The Cyber Security Transformation Podcast
Share on
Copy link to clipboard

JC Gaillard and his guests share their views on both the interesting cybersecurity news stories of the week and their own experiences. Now entering its second series with a stronger focus on cyber security governance and related board-level matters Please feel free to reach out to find out more Jean Christophe Gaillard M: +44 (0)7733 001 530 E: jcgaillard@corixpartners.com https://twitter.com/Corix_JC https://twitter.com/CorixPartners https://twitter.com/TCyberCast

Corix Partners


    • Oct 17, 2024 LATEST EPISODE
    • every other week NEW EPISODES
    • 12m AVG DURATION
    • 108 EPISODES


    Search for episodes from The Cyber Security Transformation Podcast with a specific topic:

    Latest episodes from The Cyber Security Transformation Podcast

    Series 5 - Final Episode - "A Look Back at the CrowdStrike Incident and the Meaning of Cyber Resilience" - Episode 25

    Play Episode Listen Later Oct 17, 2024 15:42


    In this final episode of the series, JC Gaillard and guest Steve Lamb take another look at the CrowdStrike incident and analyze what cyber resilience needs to mean for businesses.

    Series 5 - "A Round-up of Key Issues around Cybersecurity and Generative AI" - Episode 24

    Play Episode Listen Later Oct 3, 2024 8:39


    In this episodes, JC Gaillard focuses on the impact generative AI could be having on cybersecurity practices and goes back to number of key aspects he has been exploring in earlier episodes in this series.

    Series 5 - "The Cybersecurity Spiral of Failure: What It Is, and How to Break out of It" - Episode 23

    Play Episode Listen Later Sep 24, 2024 13:06


    In this episode, JC Gaillard looks back at the dynamics of the "Cybersecurity Spiral of Failure" and the levers top executives can action to break out of it; this is the theme of his second book, released on Amazon in January 2024 and listeners can buy the book here

    Series 5 - "The Way Forward with Cybersecurity Operating Models" - Episode 22

    Play Episode Listen Later Sep 17, 2024 9:38


    In this episode, JC Gaillard looks back at the "What", the "How" and the "Who" of change around cybersecurity - as mentioned in episode 21 - and what it takes to build or rebuild a successful cybersecurity operating model; the 2021 Corix Partners white paper on the theme can be downloaded here

    Series 5 - "Three Questions and a Reality Check around the Role of the Board with Cybersecurity" - Episode 21

    Play Episode Listen Later Sep 10, 2024 9:01


    In this episode, JC Gaillard looks back at cybersecurity governance challenges in the light of a recent article from McKinsey and offers his views on the matter, echoing a number of topics already discussed in earlier episodes of the podcast; the McKinsey article can be found here; JC's original article on the theme can be found here

    Series 5 - "Post-Quantum Cryptography: Why It Matters, and What to Do Now?" - Episode 20

    Play Episode Listen Later Sep 3, 2024 19:38


    In this episode, JC Gaillard and guest Steven O'Sullivan from Cystel look at the challenges of post-quantum cryptography in the light of the release by the U.S. NIST of new standards in that space

    Series 5 - "Teaching the Board to Talk to CISOs" - Episode 19

    Play Episode Listen Later Aug 27, 2024 7:11


    In this episode, JC Gaillard revisits the issues at the heart of the interaction between the CISO and the Board and highlights why a sense of context is key to establishing meaningful exchanges around cybersecurity; read his original article on the theme ⁠⁠here

    Series 5 - "Cyber Resilience: Real New Practice or Just a Coat of Paint on Some Old Concepts?" - Episode 18

    Play Episode Listen Later Aug 20, 2024 8:04


    In this episode, JC Gaillard looks back at cyber resilience in the light of previous podcast episodes and offers his views around a recent HBR article on the topic; the HBR article mentioned in the podcast can be found here

    Series 5 - "Using AI to Talk to the Board about Cyber: Clever Ploy or False Good Idea?" - Episode 17

    Play Episode Listen Later Aug 12, 2024 8:08


    In this episode, JC Gaillard revisits the intersection between generative AI and cybersecurity, in a complement to the topics explored in episodes 6 and 12 in the first part of Series 5

    Series 5 - "The CrowdStrike Outage Under the Spotlight: Cybersecurity Incident ? or Not?"" - Episode 16

    Play Episode Listen Later Aug 5, 2024 16:24


    In this episode, JC Gaillard and Chris Burtenshaw from Strata Security look back at the recent Crowdstrike outage and analyse the first implications from the incident

    Series 5 - "Cybersecurity: The Key Ingredient is Trust, not Money" - Episode 15

    Play Episode Listen Later Jul 30, 2024 7:06


    In this episode, JC Gaillard analyses a recent article from Hacker News and highlights his take on the 5 key questions CISOs should ask about their cybersecurity strategy; read his original article on the theme ⁠here

    Series 5 - "The Misleading Messages of the Technology Industry around Cybersecurity" - Episode 14

    Play Episode Listen Later Jun 6, 2024 8:32


    In this episode, JC Gaillard looks back at the various messages at the heart of the storytelling of security vendors, and highlights why true independence is a rare but essential commodity in the cybersecurity world; read his original article on the theme here

    Series 5 - "Knee-Jerk Reactions to Data Breaches are damaging the case for Cybersecurity" - Episode 13

    Play Episode Listen Later May 30, 2024 8:24


    In this episode, JC Gaillard goes back to the dynamics surrounding the procurement of cybersecurity tools and explains why cybersecurity transformation is not - and cannot be - about implementing yet another technology product; read his original article on the theme here

    Series 5 - "Generative AI in Cybersecurity: Incremental or Disruptive Innovation?" - Episode 12

    Play Episode Listen Later May 23, 2024 9:31


    In this episode, JC Gaillard shares his - still evolving - views on the impact Generative AI can have on cybersecurity and reflects on how the situation have evolved (or not) since his first article on the theme back in 2018

    Series 5 - "Large Enterprises Can't Cope With More Cybersecurity Tools" - Episode 11

    Play Episode Listen Later May 16, 2024 7:35


    In this episode, JC Gaillard goes back to the topic of security tools proliferation discussed in previous series and highlights why it should be central to the role of the CISO to build a vision and a product strategy, and drive the decluttering of cybersecurity landscapes

    Series 5 - "Leadership: The Real Secret Sauce for the CISO" - Episode 10

    Play Episode Listen Later May 9, 2024 12:59


    In this episode, JC Gaillard looks back at the role of the CISO, how it has evolved over the past two decades and where the priorities should be to drive real and lasting transformation around cybersecurity; read his interview on the theme ⁠here

    Series 5 - "Time to Start Focusing on the Decluttering of the Cyber Security Toolkit Landscape" - Episode 9

    Play Episode Listen Later May 2, 2024 12:24


    In this episode, JC Gaillard looks back a the cybersecurity toolkit landscape and the issues already highlighted in earlier series of the podcast and put things in perspective around the need to declutter; read his interview on the theme here

    Series 5 - "Why Are Security Vendors So Obsessed with Board Attention?" - Episode 8

    Play Episode Listen Later Apr 25, 2024 7:47


    In this episode, JC Gaillard explores the relationship between cybersecurity vendors and Board oversight, why they appear to be so driven by it and where their arguments often appear to be flawed

    Series 5 - "A Look Back at the Role of the Board around Cybersecurity Oversight" - Episode 7

    Play Episode Listen Later Apr 18, 2024 9:52


    In this episode, JC Gaillard looks back at a number of cybersecurity governance aspects he has written or spoken over the past few months, in the light of a recent report by Diligent and Bitsight

    Series 5 - "Generative AI and Cybersecurity: The Big Untold Problem" - Episode 6

    Play Episode Listen Later Apr 11, 2024 8:27


    In this episode, JC Gaillard makes a rare foray in the field of Artificial Intelligence and generative AI and highlights what he sees as the big untold problem at the heart of many discussions on the theme

    Series 5 - "From Threat to Risk: A "threat" is not a "risk" if you are well protected" - Episode 5

    Play Episode Listen Later Apr 4, 2024 9:21


    In this episode, JC Gaillard talks around the concept of risk and the importance of using accurate and rigourous language around those aspects across the cybersecurity industry; read more about the approach he highlights in this whitepaper

    Series 5 - "Looking Back at the Role of the Virtual CISO and the Reality of Small Firms" - Episode 4

    Play Episode Listen Later Mar 27, 2024 7:49


    In this episode, ⁠JC Gaillard⁠ looks back at the role of the virtual CISO and in particular why many small firms would often benefit from looking internally first, before jumping to externalised cybersecurity solutions; read his original article on the theme ⁠⁠here

    Series 5 - "Cybersecurity is Not Working: Time to Try Something Else" - Episode 3

    Play Episode Listen Later Mar 21, 2024 9:50


    In this episode, JC Gaillard continues his journey across cybersecurity governance matters, and in particular he goes back to the construction of the role of the CISO and why it is essential to put it back in its historical perspective; read his original article on the theme ⁠here

    Series 5 - "Don't Expect Cybersecurity to Work in Firms where Nothing Does" - Episode 2

    Play Episode Listen Later Mar 14, 2024 8:21


    In this episode, JC Gaillard continues to explore cybersecurity governance and in particular, why it is essential to place it in a broader corporate governance context; read his original article on the theme ⁠here

    Series 5 - "Cybersecurity Governance, Compliance and Window-Dressing" - Episode 1

    Play Episode Listen Later Mar 7, 2024 10:34


    In this first episode of the series, JC Gaillard explores issues around cybersecurity governance and ownership and in particular, why cyber resilience needs clear accountability from the top; read his original article on the theme here The UK Government "call for views" around a proposed "Cyber Governance Code of Practice" mentioned in the episode can be found here

    Series 4 - Final Episode in the Series - "One Last Look at the Role of the Board around Cybersecurity" - Episode 24

    Play Episode Listen Later Oct 26, 2023 11:59


    In this final episode of Series 4, JC Gaillard goes back to the role of the Board in relation to cybersecurity and clarifies a number of aspects from earlier episodes; read his original article on the theme here

    Series 4 - "Cybersecurity, Cycles and Predictions" - Episode 23

    Play Episode Listen Later Oct 19, 2023 7:49


    As we reach that time in the journalistic calendar where predictions for the year to come start to appear, JC Gaillard reflects on what it means for the cybersecurity industry and the real cycles over which it has been evolving

    Series 4 - "Everybody is talking about Cyber Resilience, but what do they really mean?" - Episode 22

    Play Episode Listen Later Oct 12, 2023 12:13


    In this episode, JC Gaillard explores the meaning of cyber resilience across the industry, why some many people use the term to mean so many different things and what can be done to harmonise the approach to the concept; read his original (2019) article on the theme here

    Series 4 - "The Board needs to own cybersecurity in business terms, not in technology terms" - Episode 21

    Play Episode Listen Later Oct 5, 2023 12:28


    In this episode, JC Gaillard goes back to the discussions in Episode 14 and 16 and continues to analyse the comments received in response to his earlier article around the failed role of the CISO; in this episode, more on the role of the Board and why it needs to own cybersecurity in business terms, not in technology terms.

    Series 4 - "The Relationship between the CISO and the Board: What's Really Going On?" - Episode 20

    Play Episode Listen Later Sep 28, 2023 10:08


    In this episode, JC Gaillard starts to explore the nature and the mechanics of the relationship between the CISO and the Board, in the light of two recent surveys and their conflicting headlines; References: The ComputerWeekly article mentioned in the episode can be found here; The InfoSecurityMag article can be found here; and the Proofpoint report "Cybersecurity: The 2023 Board Perspective" here

    Series 4 - "The Cybersecurity Spiral of Failure" - Episode 19

    Play Episode Listen Later Sep 21, 2023 8:27


    In this episode, JC Gaillard looks back at what has been happening in some large organisations around cybersecurity across the last two decades, and at the dynamics of what he has been calling the "cybersecurity spiral of failure"; read his original article on the theme here

    Series 4 - "A Recruitment Perspective on the Role of the CISO" - with guest Owanate Bestman - Episode 18

    Play Episode Listen Later Sep 14, 2023 26:27


    In this episode, JC Gaillard looks back at the role of the CISO in the light of discussions on the theme in the last few episodes, and takes a recruitment perspective on the role, its history and its evolution with guest and recruitmemnt specialist Owanate Bestman; some of JC's views on the topic can be found here; Owanate's profile can be found here

    Series 4 - "Why are we still talking about the reporting line of the CISO?" - with guest Mark Segelov - Episode 17

    Play Episode Listen Later Sep 7, 2023 20:05


    In this episode, JC Gaillard and guest Mark Segelov look back at the reporting line of the CISO, and why it is still a hot topic of discussion amongst cybersecurity professionals; JC's views on the topic can be found in those 2 pieces from 2017 and 2018, which are revisited in the podcast; Mark's Linkedin profile can be found here

    Series 4 - "Is it time to accept that the role of the CISO may be failing? - part 2" - Episode 16

    Play Episode Listen Later Aug 31, 2023 12:49


    In this episode, JC Gaillard goes back to the content of Episode 14 and explores a number of comments received on Linkedin around the associated article, and in particular, how the role of the CSO needs to be conceived and positioned, and the importance of a structured cybersecurity operating model

    Series 4 - "The Key Ingredients of a Successful GRC Programme" - Episode 15

    Play Episode Listen Later Aug 24, 2023 7:17


    In this episode, JC Gaillard looks back at IT GRC programmes, why they often fail, and why integration of business threats, technology risks, controls and protective measures is key to success; read his original article on the theme here.

    Series 4 - "Is it time to accept that the role of the CISO may be failing?" - Episode 14

    Play Episode Listen Later Aug 17, 2023 8:52


    In this episode, JC Gaillard revisits earlier discussions around the role of the CISO, highlighting issues with the historical construction of the role and why a CSO role may be the way forward in some firms; read his original article on the theme here

    Series 4 - "From Vendor Risk to Supply Chain Risk - Part 2" - with guest Richard Preece - Episode 13

    Play Episode Listen Later Aug 10, 2023 19:57


    In this episode, JC Gaillard and Richard Preece continue their exchanges initiated in Episode 6 of this series around supply chain risk and comment on the outcome of the Security Transformation Research Foundation meeting in late June

    Series 4 - "The Cybersecurity Numbers Game is a Dangerous One for CISOs" - Episode 12

    Play Episode Listen Later Aug 3, 2023 8:15


    In this episode, JC Gaillard revisits two apparently conflicting vendor surveys and explores how playing the cybersecurity numbers game can leave CISOs weakened and exposed; read his original article on the theme here

    Series 4 - "A Reality Check Around Cybersecurity Benchmarking" - Episode 11

    Play Episode Listen Later Jul 27, 2023 7:47


    In this episode, JC Gaillard looks at the challenges involved with cybersecurity benchmarking, and why the CISOs need to be careful when answering what could be a politically loaded question

    Series 4 - "The Momentum Building Behind the Role of the CSO" - Episode 10

    Play Episode Listen Later Jul 20, 2023 8:13


    In this episode, JC Gaillard explores the momentum behind the role of the Chief Security Officer and why it starts to make sense in many firms to evolve the role of the CISO and return it to its native technical content

    Series 4 - "Creating Transformational Dynamics around Cybersecurity" - Episode 9

    Play Episode Listen Later Jul 13, 2023 7:57


    In this episode, JC Gaillard explores the dynamics of change around cybersecurity in the light of this article from the Harvard Business Review, and highlights two essential steps for success; read his original article on the theme here

    Series 4 - "The CISO and the Board" - Episode 8

    Play Episode Listen Later Jul 6, 2023 8:12


    In this episode, JC Gaillard looks back at a recent survey from IANS Research and questions whether you should really expect your current CISO to sit on the Board; read his original article on the theme here

    Series 4 - "Dispelling Some Myths around Cybersecurity for Small Businesses" - Episode 7

    Play Episode Listen Later Jun 29, 2023 9:27


    In this episode, JC Gaillard addresses the challenges of cybersecurity for small and mid-size businesses and in particular how a number of misconceptions still lead to the adverse prioritisation of security matters and protective measures; read his original article on the theme here

    Series 4 - "From Vendor Risk to Supply Chain Risk" - with guest Richard Preece - Episode 6

    Play Episode Listen Later Jun 22, 2023 11:43


    In this episode, JC Gaillard and guest Richard Preece start exploring the various dimensions involved in managing supply chain risk, what it means for businesses, and how it differs from traditional vendor risk.

    Series 4 - "There Are Just Too Many Security Tools and Products" - Episode 5

    Play Episode Listen Later Jun 15, 2023 7:34


    In this episode, JC Gaillard looks back at the state of the cybersecurity industry and analyzes possible reasons behind the proliferation of security tools and services, and the problems it creates for large organizations; read his original article on the theme here

    Series 4 - "The When-Not-If Paradigm: Blessing or Curse for the CISO?" - Episode 4

    Play Episode Listen Later Jun 8, 2023 8:35


    In this episode, JC Gaillard goes back to the "when-not-if" paradigm around cyber attacks, which he mentioned in previous episodes, and explores its impact for the CISO; read his original article on the theme here

    Series 4 - "What's going on with CISOs and their budgets?" - Episode 3

    Play Episode Listen Later Jun 1, 2023 8:48


    In this third episode of our fourth series, JC Gaillard looks back at cybersecurity budgets and analyzes the reasons behind the considerable underspent highlighted by a recent survey; read his original article on the theme here

    Series 4 - "Zero-Trust is not about Zero; it's about Trust" - Episode 2

    Play Episode Listen Later May 25, 2023 9:07


    JC Gaillard looks back at a number of aspects involving zero-trust technology and why putting technology first is probably the biggest mistake you can make in that space; read his original article on the theme here

    Series 4 - "Time to Go Back to Basics with Cyber Security" - Episode 1

    Play Episode Listen Later May 18, 2023 9:24


    Welcome to the 1st episode of our 4th Series - JC Gaillard starts to look back at the various topics that have been catching his eye since the end of the previous series: In this episode, why it is key to look beyond the hype on a number of tech matters and refocus our approach to cyber security on key concepts; read his original article on the theme here

    Series 3 - "Process and People first, then Technology" - Episode 24

    Play Episode Listen Later Oct 18, 2022 7:44


    JC Gaillard reaches the final episode in this third series of the Corix Partners Cyber Security Transformation Podcast, and revisits a few key aspects highlighted throughout the series, in particular the importance of the "Process and People first, then Technology" principle

    Series 3 - Looking back at "The First 100 Days of the New CISO" - Episode 23

    Play Episode Listen Later Oct 11, 2022 9:42


    JC Gaillard continues to analyze the way the various aspects highlighted in earlier episodes of the Series are interlinked; in this episode, he goes back to the "when-not-if" paradigm around cyber attacks and why tactical and strategic execution is paramount for the new CISO

    Claim The Cyber Security Transformation Podcast

    In order to claim this podcast we'll send an email to with a verification link. Simply click the link and you will be able to edit tags, request a refresh, and other features to take control of your podcast page!

    Claim Cancel