Podcasts about ciso series

  • 16PODCASTS
  • 1,838EPISODES
  • 21mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Aug 27, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about ciso series

Latest podcast episodes about ciso series

Defense in Depth
Market Confusion Is Responsible for the Biggest Gaps in Cybersecurity

Defense in Depth

Play Episode Listen Later Aug 27, 2026 29:47


All links and images can be found on CISO Series Check out this post from Joe Head of RELEX Solutions for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining is Mary Rose Martinez, CISO, and vp of digital technology services, Marathon Petroleum Corporation. In this episode: Left behind A hypothetical sale The philosophy problem Stop shifting the problems A huge thanks to our sponsor, ActiveState ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time. Learn more at activestate.com.

CISO-Security Vendor Relationship Podcast
"Ignorance Is Bliss" Is Our Acceptable Use Policy

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Aug 25, 2026 39:03


http://www.Threatlocker.com/cisoAll links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series and Edward Contreras, senior evp and CISO, Frost Bank. Joining is sponsored guest Rob Allen, chief product officer, ThreatLocker. In this episode: Not my job, still my problem The tools people actually use Mac, Windows, and the debate that won't quit Hiring for imagination, not acronyms A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.

hiring mac windows ciso ignorance is bliss rob allen threatlocker frost bank david spark zero trust network access acceptable use policy ciso series
Defense in Depth
Will AI Replace Detection Roles in Cybersecurity?

Defense in Depth

Play Episode Listen Later Aug 20, 2026 35:13


All links and images can be found on CISO Series Check out this post from Caleb Sima of Whiterabbit for the discussion that is the basis of our conversation on this week's episode co-hosted David Spark, the producer of CISO Series, and Yaron Levi, CISO, Dolby. Joining is Adrian Ludwig, CSO, Rippling. In this episode: The messy middle The automatable part Where automation stops The influence gap A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.

CISO-Security Vendor Relationship Podcast
Secure by Design. Ignored by Default.

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Aug 18, 2026 37:55


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining is Julie Davila, president, Security Tinkerers. In this episode: Two paths, one dead end One size fits nobody Own it or orphan it The agent you should worry about A huge thanks to our sponsor, Guardsquare Guardsquare delivers mobile app security without compromise, providing advanced protections for both Android and iOS apps. From app security testing to code hardening to real-time visibility into the threat landscape, Guardsquare solutions provide enhanced mobile application security from early in the development process through publication. Learn more about how to protect your app at Guardsquare.com/CISO.

Defense in Depth
What Makes a Good AI Security Deployment?

Defense in Depth

Play Episode Listen Later Aug 13, 2026 31:19


What Makes a Good AI Security Deployment? All links and images can be found on CISO Series Check out this post by Chris Matthews of UpGuard for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Peter Liebert, CISO, Salesloft & Clari. In this episode: Non-determinism changes everything The foundation problem Nobody owns the whole problem The authorization gap A huge thanks to our sponsor, CoreView Attackers don't break into Microsoft 365. They log in and reconfigure it. When tenant configurations drift or get tampered with, recovery can take weeks and missed settings can reopen the door. The Cyber Resilience Framework for Microsoft 365 covers the five pillars, harden, govern, detect, respond, recover, and shows exactly where today's tools leave gaps. Download the free practical guide  

microsoft deployment ciso chris matthews ai security frost bank david spark upguard ciso series
CISO-Security Vendor Relationship Podcast
Why Solve Your Problems When We Can Just Scare You?

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Aug 11, 2026 41:15


All links and images can be found on CISO Series This week's episode is hosted by me, David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is Nada Noaman, SVP and CISO, Estee Lauder Companies. In this episode: Skipping the apprenticeship Privileged users nobody manages like one Findings without the authority to fix them Security was always behavioral A huge thanks to our sponsor, Native The Cloud Security Control Plane. Native helps enterprises turn built-in cloud security controls into active, operational defenses across AWS, Azure, Google Cloud, and OCI, so teams can enforce secure-by-design architecture at the source, preview impact before rollout, and keep guardrails aligned as cloud environments change. Learn more at native.security.  

Defense in Depth
The Office Politics of Remediation

Defense in Depth

Play Episode Listen Later Aug 6, 2026 28:48


All links and images can be found on CISO Series Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Dan Walsh, CISO, Datavant. Joining is our sponsored guest, Elizabeth Nammour, founder and CEO, Teleskope. In this episode: Data ownership before automation A shared vocabulary for agent risk Maturing from crawl to run Trust earns automation its place A huge thanks to our sponsor, Teleskope Most DSPMs stop at finding the risk. Teleskope fixes this: it automatically finds sensitive data, including IP documents or board decks, and remediates exposure across cloud, SaaS, and AI environments natively, with human-in-the-loop controls, improving your team's efficiency tenfold. Trusted by Ramp, Polymarket, and Chevron Phillips, and more. teleskope.ai  

CISO-Security Vendor Relationship Podcast
See, Our Compliance Framework Includes a Checkbox for Resilience

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Aug 4, 2026 43:43


All links and images can be found on CISO Series This week's episode is hosted by me, David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is our sponsored guest, Khush Kashyap, senior director of GRC at Vanta. In this episode: Running up the token meter Some risks resist a price tag Resilience isn't a vacation policy Compliance is the wrong finish line A huge thanks to our sponsor, Vanta Still stuck on the quarterly audit treadmill? Meet Calm-pliance. Vanta combines compliance, risk, and proof on one Agentic Trust Platform—and continuously monitors your controls, keeping you audit-ready all year round. Find your Calm-pliance here.

Cyber Security Headlines
The Department of Know: Minnesota water hack, LLM finds encryption flaw, human error hit Hugging Face

Cyber Security Headlines

Play Episode Listen Later Jul 31, 2026 30:24


This week's Department of Know is hosted by Rich Stroffolino, with guests Janet Heins, CISO, ChenMed, and Derek Fisher, Director of the Cyber Defense and Information Assurance Program, Temple University. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing. It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.

Defense in Depth
Why is Preventative Security So Difficult?

Defense in Depth

Play Episode Listen Later Jul 30, 2026 30:16


All links and images can be found on CISO Series Prevention in cybersecurity is a lot like flossing: everyone knows they should do it, but few do it enough. What's stopping us? Check out this post by Ross Haleliuk of Venture in Security for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Deneen DeFiore, vice president & chief information security officer, United Airlines. In this episode: The sponsorship gap One strike and you're out Policy without position Prevention isn't static A huge thanks to our sponsor, CoreView Attackers don't break into Microsoft 365. They log in and reconfigure it. When tenant configurations drift or get tampered with, recovery can take weeks and missed settings can reopen the door. The Cyber Resilience Framework for Microsoft 365 covers the five pillars, harden, govern, detect, respond, recover, and shows exactly where today's tools leave gaps. Download the free practical guide

CISO-Security Vendor Relationship Podcast
Why Don't You Tell Me Which Metrics Sound Most Impressive?

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jul 28, 2026 48:02


All links and images can be found on CISO Series This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining is Pavi Ramamurthy, Global CISO and CIO, Blackhawk Network. In this episode: Numbers that make the board feel good and nothing else The audit is not the same thing as the truth Receipts aren't a strategy Stop blaming the human, fix the system they're standing in A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.  

sound numbers metrics cio impressive receipts ciso duha andy ellis global ciso threatlocker david spark zero trust network access blackhawk network ciso series
Cyber Security Headlines
The Department of Know: OpenAI hacks Hugging Face, Chinese LLM ban, Kratos takedown

Cyber Security Headlines

Play Episode Listen Later Jul 24, 2026 34:41


This week's Department of Know is hosted by Rich Stroffolino, with guests Nick Espinosa, host, Deep Dive Radio Show, and Dennis Pickett, vp, CISO, Westat. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai. Stay safe - Quilr it.

Defense in Depth
Identity and Access Management (IAM) in an Agentic AI World

Defense in Depth

Play Episode Listen Later Jul 23, 2026 30:20


All links and images can be found on CISO Series Check out this post by Tomás Maldonado, CISO, NFL, for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Yaron Levi, CISO, Dolby. Joining is Will Gregorian, vp of information technology & security, Galileo Medical. In this episode: From who to what The manipulation problem Cryptographic accountability The audit gap A huge thanks to our sponsor, ActiveState ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time. Learn more at ActiveState.com.

CISO-Security Vendor Relationship Podcast
With AI, I Can Now Be Pulled in 5x More Directions at Once!

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jul 21, 2026 47:35


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining is our sponsored guest, Brian Long, CEO, Adaptive Security. In this episode: Nobody clocks out anymore The rules nobody wrote down are the ones that count AI doesn't drain your empathy, it just shows your hand Loyalty runs both directions, even out the door A huge thanks to our sponsor, Adaptive Security Adaptive Security helps organizations stay ahead of AI-powered social engineering, including deepfake phishing, vishing, and multi-channel attacks. With simulations and personalized training, teams learn to recognize and respond to modern threats before they cause harm. Turn human risk into resilience with security awareness built for the AI era. Learn more at adaptivesecurity.com.

ceo ai loyalty pulled directions duha andy ellis brian long david spark ciso series
Cyber Security Headlines
The Department of Know: CMMC suspended, ShareFile shutdown, Context Bombing strikes back

Cyber Security Headlines

Play Episode Listen Later Jul 17, 2026 42:58


"Context Bombing" flips the script on prompt injections Pentagon suspends CMMC Phase II requirements Old tech, new problems Get the show notes here: https://cisoseries.com/the-department-of-know-cmmc-suspended-sharefile-shutdown-context-bombing-strikes-back/  This week's Department of Know is hosted by Rich Stroffolino, with guests Tom Hollingsworth, networking technology advisor, Futurum Group, and Mark Eggleston, former CISO, CSC. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines.  Because security works best when innovation and control move together.

Defense in Depth
Protecting AI Agents in O365 and Google Workspace

Defense in Depth

Play Episode Listen Later Jul 16, 2026 33:53


All links and images can be found on CISO Series Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining is their sponsored guest, Rajan Kapoor, vp, security, Material Security. In this episode: Pre-existing conditions Architecture over rollout Access isn't legitimacy Data has a half-life A huge thanks to our sponsor, Material Security Legacy email security only watches the door. Material protects your entire cloud workspace—email, files, and accounts—as one ecosystem. It's more coverage for less than the cost of a legacy SEG. One price, no surprises: just security that covers the whole surface area. Learn more at material.security.

data protecting architecture material google workspace o365 david spark material security ciso series
CISO-Security Vendor Relationship Podcast
The Only Thing Worse Than Technical Debt is Newly Discovered Technical Debt

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jul 14, 2026 43:57


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining them is Tim Callahan, CIO/CISO, AFLAC. In this episode: Week one is the wrong time to overreach Nobody has the AI playbook Vulnerability management wasn't built for this clock Stop blaming the human, fix the system A huge thanks to our sponsor, Vanta No, it's not your imagination. Risk and regulations ARE ramping up—and customers now expect proof of security just to do business. That's why Vanta is a game-changer. Vanta automates your compliance process and brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Companies like Ramp and Writer spend 82% less time on audits with Vanta. That's not just faster compliance—it's more time for growth. Get started at Vanta.com/CISO.  

Cyber Security Headlines
The Department of Know: France gets ready for quantum, JadePuffer ransomware, UK's Cyber Shield

Cyber Security Headlines

Play Episode Listen Later Jul 10, 2026 39:35


Link to the episode This week's Department of Know is hosted by Rich Stroffolino, with guests Davi Ottenheimer, principal, Flying Penguin, and Chris Ray, field CTO, GigaOm. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines. 

ai france missed shield cto cyber quantum ransomware ramp cursor grc vanta gigaom chris ray davi ottenheimer ciso series rich stroffolino
Defense in Depth
Humans Are Bottleneck in a Machine-Speed World

Defense in Depth

Play Episode Listen Later Jul 9, 2026 35:36


  All links and images can be found on CISO Series We're evolving fast to secure AI. But are we evolving fast enough to secure WITH AI? Check out this post by Rinki Sethi, CSO, Upwind Security, for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Howard Holton, former CEO, GigaOm. Joining is Adam Glick, CSO, PSG Equity. In this episode: Human-in-the-loop math Should machines decide at all From assistant to autonomous Redefining the security role A huge thanks to our sponsor, Palo Alto Networks   Cortex Cloud unifies code, cloud, and SOC on a single data, risk, and control plane — giving teams the context, workflows, and agentic intelligence to turn risk into resolution. Native AI agents investigate and act within enterprise guardrails, delivering real-time protection from workload to network edge. Cloud security that outpaces machine-speed threats. Visit paloaltonetworks.com/cortex/cloud.

ceo ai human humans cloud redefining cso soc bottleneck gigaom david spark speed world adam glick ciso series
CISO-Security Vendor Relationship Podcast
What Part of Zero Trust Does Your Exception Not Understand?

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jul 7, 2026 37:46


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining is Patti Degnan, operating partner, Andreessen Horowitz. In this episode: Identity built for one person at a time Patching can't outrun the exploit timeline The exception hiding inside zero trust A revenue question nobody's answered yet A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.

Defense in Depth
Even With All These Security Vendors We Still Have Glaring Gaps

Defense in Depth

Play Episode Listen Later Jul 2, 2026 33:56


All links and images can be found on CISO Series There are thousands of cybersecurity vendors across categories. If there's a gap in the market, it's likely not for technical reasons. So, how do you actually find vendors that are a good fit rather than one that just meets technical requirements? Check out this post by Joe Head of REFLEX Solutions for the discussion that is the basis of our conversation on this week's episode, co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Ajit Girn, CIO, Employment Development Department (EDD). In this episode: Built for vendors, not users Signal versus noise Priced out The elegance gap A huge thanks to our sponsor, ThreatLocker ThreatLocker takes a deny-by-default approach to endpoint security — controlling what applications can run, what can access data, and what can elevate privileges. Used by organizations that want to reduce attack surface without relying on detection alone. Learn more at threatlocker.com/ciso.

CISO-Security Vendor Relationship Podcast
These Aren't Speed Bumps, They're Opportunity Ramps! (LIVE in NYC)

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jun 30, 2026 42:20


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series and Nick Vigier, CISO, Oscar Health. Joining is our sponsored guest, Mitchem Boles, field CTO, Intezer. This episode was recorded live at Intezer's AI SOC event held at the NASDAQ in NYC. In this episode: Who owns the risk Before it gets better The SOC of zero The decision bottleneck A huge thanks to our sponsor, Intezer Intezer Forensic AI SOC is designed for enterprises managing high alert volumes across SIEM, EDR Network, identity, phishing, and cloud systems. These organizations often rely on MDRs to fill coverage gaps but face frustration with limited visibility, too many escalations, and missed incidents hiding in low-severity alerts. Learn more at Intezer.com.

Defense in Depth
Is the "Attackers Only Need to Be Right Once" a Misnomer?

Defense in Depth

Play Episode Listen Later Jun 25, 2026 27:40


All links and images can be found on CISO Series Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and George Finney, CISO, University of Texas System. Joining is Sean Walls, CISO, Bob's Discount Furniture. In this episode: Asymmetric accounting Sometimes it really is that easy The spirit of the saying The cheapest way in A huge thanks to our sponsor, Native Security Native is the Cloud Security Control Plane. It helps enterprises enforce secure-by-design architecture across multi-cloud environments by translating security intent into the cloud provider's built-in controls, previewing impact before rollout, and keeping enforcement aligned as the environment changes.

university attackers ciso asymmetric misnomer texas system david spark ciso series
CISO-Security Vendor Relationship Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jun 23, 2026 40:09


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining is Megan Samford, vp product and supply chain security, Schneider Electric. In this episode: Two modes of CISO The vendor has the keys The economic argument for secure code Burning through the talent A huge thanks to our sponsor, Native Security Native makes secure-by-design inherent to how the cloud operates. It's the control plane for built-in cloud security, unifying and governing native controls, so security intent is defined once and applied consistently across providers. Learn more at native.security.

Defense in Depth
What It Takes To Be Successful in Cyber Media

Defense in Depth

Play Episode Listen Later Jun 18, 2026 55:27


What It Takes To Be Successful in Cyber Media All links and images can be found on CISO Series Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Dave Bittner, producer and host, The CyberWire. Joining is Graham Cluley, host of Smashing Security podcast and Leo Laporte, founder of TWiT (This Week in Tech) and host of Security Now podcast. In this episode: Format follows function The decision gap Practitioner fingerprints Beyond the news cycle A huge thanks to our sponsor, Palo Alto Networks Cortex Cloud unifies code, cloud, and SOC on a single data, risk, and control plane — giving teams the context, workflows, and agentic intelligence to turn risk into resolution. Native AI agents investigate and act within enterprise guardrails, delivering real-time protection from workload to network edge. Cloud security that outpaces machine-speed threats. Learn more at paloaltonetworks.com/cortex/cloud/demo.

media cloud cyber practitioners soc leo laporte security now cyberwire david spark graham cluley smashing security dave bittner ciso series
CISO-Security Vendor Relationship Podcast
Boards Love to Hear Jargon," Says Soon-to-Be-Fired CISO (LIVE in Boston)

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jun 16, 2026 48:22


All links and images can be found on CISO Series This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining us is Dmitriy Sokolovskiy, senior vice president, information security, Semrush. This episode was recorded in front of a live audience at the offices of Aqueduct Technologies in Canton, MA. See photos from the event. In this episode: A clock on everything The oversight loop Not a better tool, a different one It's not the alerts A huge thanks to our sponsor, Strike48 It's no secret that AI is only as good as the data available to it. Strike48 unifies agentic AI with unmatched log visibility while avoiding the typical hefty price tag. Build and deploy agents for phishing detection, alert triage, threat correlation and more. Queries existing logs where they currently live, so you can keep the technology you already have. Learn more at Strike48.com.   A huge thanks to our sponsor, Dropzone AI Dropzone AI delivers a team of AI agents that investigate alerts, hunt threats, and respond to attacks across your full security stack. No playbooks required. No hidden humans in the critical path. Your analysts stay in control, directing strategy while AI agents handle the investigation workload at machine speed. Learn more at dropzone.ai.

Cyber Security Headlines
The Department of Know: CISA's quick patch, Miasma attacks, judge finds AI guilty

Cyber Security Headlines

Play Episode Listen Later Jun 12, 2026 38:26


This week's Department of Know is hosted by Rich Stroffolino, with guests Brett Conlon, CISO, American Century Investments, and Jason Thomas, senior director, technology security, governance, and risk, Cystic Fibrosis Foundation. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our episode sponsor, Doppel Cybercriminals don't respect your security silos. They use one connected attack chain to hit your brand externally, infiltrate your inbox, and manipulate your team. Stop playing whack-a-mole with fragmented tools. Doppel unifies Digital Risk Protection, Human Risk Management, and Email Security into one unified platform. One attack chain. Three pillars of defense. Zero blind spots. Secure your enterprise relentlessly at doppel.com.

Defense in Depth
CISOs Buy For Selfish and Politically Risk-Averse Reasons (Not Because Your Product is the Best)

Defense in Depth

Play Episode Listen Later Jun 11, 2026 31:21


All links and images can be found on CISO Series Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Howard Holton, CEO, GigaOm. Joining is Tyler King, senior director - threat operations and response, Sinclair. In this episode: Career insurance In the trenches together Who are you actually selling to? Common sense, uncommon in sales A huge thanks to our sponsor, Material Security Legacy email security only watches the door. Material protects your entire cloud workspace—email, files, and accounts—as one ecosystem. It's more coverage for less than the cost of a legacy SEG. One price, no surprises: just security that covers the whole surface area. Learn more at material.security.

CISO-Security Vendor Relationship Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jun 9, 2026 44:25


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining is our sponsored guest, Danny Jenkins, CEO, ThreatLocker. In this episode: Permission creep at machine speed The pattern we keep calling a mistake Stop authenticating the human Vibe coded out of existence A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.

ceo cloud permission vibe ciso screw up duha andy ellis threatlocker david spark zero trust network access danny jenkins ciso series
Cyber Security Headlines
The Department of Know: NVD audit, Meta's leaky AI, Microsoft is closer to quantum

Cyber Security Headlines

Play Episode Listen Later Jun 5, 2026 36:56


This week's Department of Know is hosted by Rich Stroffolino, with guests Robb Dunewood, host, Daily Tech News Show, and David Cross, CISO, Atlassian. Get the show notes here. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines. 

Defense in Depth
Has Cybersecurity Become a Cult?

Defense in Depth

Play Episode Listen Later Jun 4, 2026 33:57


All links and images can be found on CISO Series We think of cybersecurity as a discipline. But when do ideas like best practices and NIST frameworks change into a system of belief? Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Davi Ottenheimer, principal, Flying Penguin. Joining is Joshua Copeland, director of security, Crescendo. In this episode: Tools, not religion The case for structured discipline The management problem underneath Fix the damn holes A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.

tools cult cybersecurity fix ciso crescendo nist threatlocker david spark zero trust network access davi ottenheimer ciso series
CISO-Security Vendor Relationship Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jun 2, 2026 37:52


Our Data Security Policy Is Transparent in That It Doesn't Exist All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series, and Mike Johnson, CISO, Rivian. Joining is Mike Melo, CISO, TMX Group. In this episode: The weight of old controls Data you can actually see 68 vendors and counting Authority you never had to claim A huge thanks to our sponsor, Vanta Still stuck on the quarterly audit treadmill? Meet Calm-pliance. Vanta combines compliance, risk, and proof on one Agentic Trust Platform—and continuously monitors your controls, keeping you audit-ready all year round. Find your Calm-pliance here.

Defense in Depth
What Does the Next Generation of Cloud Security Look Like?

Defense in Depth

Play Episode Listen Later May 28, 2026 33:22


All links and images can be found on CISO Series We know human-paced security controls can't be applied to autonomous AI agents. So what needs to change with CNAPP and cloud security? Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Dan Benjamin, vp product - data, identity, and AI security, Palo Alto Networks. In this episode: The detection ceiling A category gap, not a feature gap Resilience by design An insider threat with no face A huge thanks to our sponsor, Palo Alto Networks Cortex Cloud unifies code, cloud, and SOC on a single data, risk, and control plane — giving teams the context, workflows, and agentic intelligence to turn risk into resolution. Native AI agents investigate and act within enterprise guardrails, delivering real-time protection from workload to network edge. Cloud security that outpaces machine-speed threats. Visit Palo Alto Networks and search cortex cloud.  

CISO-Security Vendor Relationship Podcast
If You Like Cloud Misconfigurations So Much, Why Don't You Marry Them!

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later May 26, 2026 40:10


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining them is their sponsored guest Amit Megiddo, CEO and founder, Native. In this episode: The CISO you don't need Misconfigurations aren't a cloud problem Secure by design means enforcing it Finding bugs faster isn't the bottleneck A huge thanks to our sponsor, Native Native makes secure-by-design inherent to how the cloud operates. It's the control plane for built-in cloud security, unifying and governing native controls, so security intent is defined once and applied consistently across providers. Learn more at native.security.  

ceo cloud secure native marry ciso duha andy ellis david spark ciso series native native
Cyber Security Headlines
The Department of Know: Google's CodeMender, CISA's big leak, Torvalds open-source warning

Cyber Security Headlines

Play Episode Listen Later May 22, 2026 42:27


This week's Department of Know is hosted by Rich Stroffolino, with guests Kathleen Mullin, former CISO, MyCareGorithm, and Nick Espinosa, host, Deep Dive Radio Show. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.  

google missed crm leak open source ciso zero trust cisa threatlocker torvalds zero trust network access ciso series rich stroffolino
Defense in Depth
The Dangers of Picking the Wrong Vendor

Defense in Depth

Play Episode Listen Later May 21, 2026 26:46


All links and images can be found on CISO Series. Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is our guest, Paul Guerra. In this episode: Read the contract How vendors win before the evaluation ends The fallout The real cost A huge thanks to our sponsor, Native Security Native makes secure-by-design inherent to how the cloud operates. It's the control plane for built-in cloud security, unifying and governing native controls, so security intent is defined once and applied consistently across providers. Learn more at native.security.

dangers picking vendor david spark paul guerra ciso series
CISO-Security Vendor Relationship Podcast
Why Be Responsible When We Can Just Blame AI?

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later May 19, 2026 41:35


All links and images can be found on CISO Series This week's CISO Series Podcast features David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining us is our sponsored guest, Jadee Hanson, CISO, Vanta. In this episode: The compliance receipt nobody reads Who signs off on the AI that wrote the code The agent that wouldn't stop The questionnaire that should not exist A huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

Cyber Security Headlines
The Department of Know: GemStuffer attack, AI SBOMs, and AI-created zero-days

Cyber Security Headlines

Play Episode Listen Later May 15, 2026 34:47


This week's Department of Know is hosted by Rich Stroffolino, with guests Gary Chan, CISO, SSM Health and Peter Liebert, CISO, Salesloft. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, Doppel Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.

Defense in Depth
Why Cyber Startups Need CISO Advisors

Defense in Depth

Play Episode Listen Later May 14, 2026 26:40


All links and images can be found on CISO Series All security startups will tell you they talk to potential customers. The problem is that you limit your development when you only talk to CISOs who might buy. It's not the same guidance you'll get from a CISO who advises. Check out this post by Val Tsanev of the Cyber Risk Alliance for the discussion that is the basis of our conversation. This week's episode is co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Steve Jensen, CISO, University of Maine System. In this episode: Building for whom? The only feedback loop that matters Valid, but for whom? Rethink the advisor roster A huge thanks to our sponsor, Material Security Legacy email security only watches the door. Material protects your entire cloud workspace—email, files, and accounts—as one ecosystem. It's more coverage for less than the cost of a legacy SEG. One price, no surprises: just security that covers the whole surface area. Learn more at material.security. 

CISO-Security Vendor Relationship Podcast
Can You Please Train the AI on Your Way Out the Door?

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later May 12, 2026 36:49


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining is Jean-Paul Calabio, vp and CISO, Grainger. In this episode: Scanning the map isn't securing the territory CFOs don't fund faith What your AI inherits Nobody owns the gap Thanks to Jonathan Waldrop, CISO, Acoustic for providing our "What's Worse" scenario. A huge thanks to our sponsor, ThreatLocker ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.

Cyber Security Headlines
The Department of Know: AI "transformation paradox," Copy Fail chaos, hacked lawnmowers

Cyber Security Headlines

Play Episode Listen Later May 8, 2026 38:41


Link to the episode This week's Department of Know is hosted by Rich Stroffolino, with guests Jonathan Waldrop, CISO, Acoustic, and Jason Elrod, CISO, MultiCare Health System. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

Defense in Depth
Breaking the Reactive Cycle of Cybersecurity

Defense in Depth

Play Episode Listen Later May 7, 2026 31:52


All links and images can be found on CISO Series. Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Rob Allen. In this episode: The vulnerable stack Changing the structural economics Change the terrain The cost-benefit equation A huge thanks to our sponsor, ThreatLocker ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.

CISO-Security Vendor Relationship Podcast
AI Confidence: It's a Trap! (LIVE in San Francisco)

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later May 5, 2026 43:28


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining is Sara Madden, CISO, Convera. This episode was recorded live at BSidesSF 2026. In this episode: Playing vendor roulette Confident and wrong Making conferences count The stakes problem in tabletops A huge thanks to our sponsor, QuilrAI Can you tell if an action in your environment was performed by a human — or an AI agent? QuilrAI's Decision Engine evaluates content, context, and intent before actions complete — across browsers, endpoints, SaaS, LLMs, and agents. Not more alerts. Better decisions, in real time. Visit quilr.ai. A huge thanks to our sponsor, Nudge Security Get a full inventory of AI assets on Day One of your free trial, even those introduced before you started using Nudge. Get started. A huge thanks to our sponsor, Zenity Help shape the future of AI agent security. On May 27th, the AI Agent Security Summit returns to San Francisco. Hear from leading researchers and security pioneers, and usher in the new age of secure AI deployment across the enterprise. Register at zenity.io/ai-security-summit.  

Defense in Depth
How Do You Know If Your Backups Will Survive a Ransomware Attack?

Defense in Depth

Play Episode Listen Later Apr 30, 2026 38:25


All links and images can be found on CISO Series Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Heath Renfrow, co-founder, Fenix24. In this episode: Knowing which systems to save first Recovery is a business conversation, not an IT ticket Not all systems are created equal Recovery knowledge as a governed asset A huge thanks to our sponsor, Fenix24   Fenix24 is the world's leading breach recovery firm, providing rapid ransomware restoration, full asset visibility, and threat informed hardening. Alongside expert recovery services, Fenix24 delivers ongoing managed protection that secures backups, infrastructure, and critical controls, helping organizations stay resilient, recoverable, and prepared for modern cyber threats. Learn more at fenix24.com.

CISO-Security Vendor Relationship Podcast
Step 1: Deploy New AI Tool. Step 2: Discover Security Flaws. Step 3: Repeat. (LIVE in Orlando)

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Apr 28, 2026 42:40


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series and Michelle Wilson, CISO, Movement Mortgage. Joining is sponsored guest Rob Allen, chief product officer, ThreatLocker. This show was recorded in front of a live audience at ThreatLocker's conference, Zero Trust World 2026. In this episode: Risk as a daily habit AI agents talking to AI agents The code on the lock Words that shape decisions A huge thanks to our sponsor, ThreatLocker ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.

Defense in Depth
What Makes a Successful Security Vendor Demo?

Defense in Depth

Play Episode Listen Later Apr 23, 2026 26:53


What Makes a Successful Security Vendor Demo? All links and images can be found on CISO Series. Check out this post from Adam Palmer for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Geoff Belknap. Joining is Ken Beasley, BISO, Kaiser Permanente. In this episode: Show me the problem, not the product Walking in blind Discovery is the demo Define the use case, set the clock A huge thanks to our sponsor, Fenix24 Fenix24 is the world's leading breach recovery firm, providing rapid ransomware restoration, full asset visibility, and threat informed hardening. Alongside expert recovery services, Fenix24 delivers ongoing managed protection that secures backups, infrastructure, and critical controls, helping organizations stay resilient, recoverable, and prepared for modern cyber threats. Learn more at fenix24.com.

CISO-Security Vendor Relationship Podcast
Back in My Day, You Could Get a Cybersecurity Job at the Corner Store

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Apr 21, 2026 39:59


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining is Paul Drapeau, head of global information security, New Balance. In this episode: The logo trap Immunity through exposure The synthesis edge The cost of holding tight A huge thanks to our sponsor, Doppel This episode is sponsored by Doppel, the AI-native social engineering defense platform. Doppel strengthens human risk management by training employees to recognize deception, while our digital risk protection detects and disrupts attacks across every channel. Learn more at doppel.com

Defense in Depth
Should You Use Native or 3rd Party Cloud Management Tools?

Defense in Depth

Play Episode Listen Later Apr 16, 2026 28:21


Should You Use Native or 3rd Party Cloud Management Tools? All links and images can be found on CISO Series. Check out this post from Steve Zalewski for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is their sponsored guest, Gal Ordo, co-founder and CPO, Native. In this episode: More tools, more problems A gap in design Catching what slips through Competence over complexity A huge thanks to our sponsor, Native Security Native makes secure-by-design inherent to how the cloud operates. It's the control plane for built-in cloud security, unifying and governing native controls, so security intent is defined once and applied consistently across providers. Learn more at native.security.

CISO-Security Vendor Relationship Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Apr 14, 2026 43:12


Our Theoretical Controls Work Great Against Hypothetical Attacks All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining is David Nolan, former CISO, Asurion. In this episode: Influence, not control The initiative gap Skip the framework, patch the server Confident code with no owner A huge thanks to our sponsor, ThreatLocker ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.

CISO-Security Vendor Relationship Podcast
Remember, Every Underappreciated Risk Is Just a Crisis Waiting to Be Discovered

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Apr 7, 2026 42:57


All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining us is Hilik Kotler, svp, CISO and IT, Expedia Group. In this episode: The numbers game What makes a vendor worth your time Humanity in the loop Alignment is a prerequisite, not a nice-to-have A huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.