• I Don’t Want Insider Risk. You Take It.
    Jul 16 2024

    All links and images for this episode can be found on CISO Series.

    This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining us is our sponsored guest, Abhishek Agrawal, CEO and co-founder, Material Security.

    In this episode:

    • What does defense in depth look like in the cloud?
    • Collaborating on insider risk
    • Email is a vector and a target
    • Understand risk during an IPO

    Thanks to our podcast sponsor, Material Security!

    Material Security is a multi-layered email threat detection & response toolkit designed to stop attacks and reduce the threat surface across all of Microsoft 365 and Google Workspace. Learn more at material.security.

    Show more Show less
    34 mins
  • How to Get the Most for Yourself Through Altruism
    Jul 9 2024

    All links and images for this episode can be found on CISO Series.

    This week’s episode is hosted by David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is Jana Moore, CISO, Belron.

    In this episode:

    • SEC disclosure rules require cyber readiness
    • Breaking up the “boys club”
    • Building a threat intelligence ecosystem
    • Blending InfoSec communities and careers

    Thanks to our podcast sponsor, Vanta!

    Whether you’re starting or scaling your security program, Vanta helps you automate compliance across SOC 2, ISO 27001, and more. Streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies use Vanta to manage risk and prove security.

    Show more Show less
    39 mins
  • Who Owns AI Risk? NOT IT!
    Jul 2 2024

    All links and images for this episode can be found on CISO Series.

    This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is our sponsored guest, Jason Clark, chief strategy officer, Cyera.

    In this episode:

    • Does AI require new security measures?
    • Meeting the new SEC requirements
    • Empowerment through data security
    • Upskilling with Gen AI?

    Thanks to our podcast sponsor, Cyera!

    Cyera’s AI-powered data security platform gives companies visibility over their sensitive data, context over the risk it represents, and actionable, prioritized remediation guidance.
 As a cloud-native, agentless platform, Cyera provides holistic data security coverage across SaaS, PaaS, IaaS and On-premise environments. Visit www.cyera.io to learn more.

    Show more Show less
    39 mins
  • How About This? Only Attack the Endpoints We Configured
    Jun 25 2024

    All links and images for this episode can be found on CISO Series.

    This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining us is our guest and winner of Season 2 of Capture the CISO, Russell Spitler, CEO and co-founder, Nudge Security.

    In this episode:

    • The Gordian knot of EDR
    • Can we keep up with patching?
    • Making AI practical
    • Standardization or granularity?

    Thanks to our podcast sponsor, ThreatLocker!

    ThreatLocker® is a global leader in Zero Trust endpoint security offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

    Show more Show less
    40 mins
  • The Post-it Note Clearly Says “Don’t Share” Right Under My Password
    Jun 18 2024

    All links and images for this episode can be found on CISO Series.

    This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is our sponsored guest, Allan Alford, CISO, Eclypsium.

    In this episode:

    • Evolving public-private partnerships
    • New technology, but not a new challenge
    • Securing the hidden layers of the supply chain
    • Balancing usability and control

    Thanks to our podcast sponsor, Eclypsium

    Eclypsium is helping enterprises and government agencies mitigate risks to their infrastructure from complex technology supply chains. Our cloud-based and on-premises platform provides digital supply chain security for software, firmware and hardware in enterprise infrastructure. Get started today at eclypsium.com/spark.

    Show more Show less
    37 mins
  • Who You Gonna Call? LEGAL COUNSEL!
    Jun 11 2024

    All links and images for this episode can be found on CISO Series.

    This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining us is our guest, Ryan Bachman, evp and global CISO, GM Financial.

    In this episode:

    • A changing of the executive guard?

    • Playing nice with cyber insurance

    • What does leadership want out of a CISO?

    • Who does a CISO call first?

    Thanks to our podcast sponsor, Vanta

    Whether you’re starting or scaling your security program, Vanta helps you automate compliance across SOC 2, ISO 27001, and more. Streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies use Vanta to manage risk and prove security.

    Show more Show less
    38 mins
  • I’m Rewarding Your Successful Use of the Security Budget by Giving You Less of It
    Jun 4 2024

    All links and images for this episode can be found on CISO Series.

    This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining me is my guest, Aamir Niazi, executive director and CISO, SMBC Capital Markets.

    In this episode:

    • Communicating security accomplishments

    • Spotting red flags in an interview

    • What does offensive security look like today?

    • Where Gen AI is fitting into cybersecurity

    Thanks to our podcast sponsor, Cyera

    Cyera’s AI-powered data security platform gives companies visibility over their sensitive data, context over the risk it represents, and actionable, prioritized remediation guidance.
 As a cloud-native, agentless platform, Cyera provides holistic data security coverage across SaaS, PaaS, IaaS and On-premise environments. Visit www.cyera.io to learn more.

    Show more Show less
    37 mins
  • Ransomware? Why’d It Have to Be Ransomware? (Live in San Francisco)
    May 28 2024

    All links and images for this episode can be found on CISO Series.

    This week’s episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is Steve Zalewski, co-host, Defense in Depth. Recorded live at BSidesSF.

    In this episode:

    • Are companies taking the air out of the open source balloon?

    • What’s broken about cybersecurity hiring?

    • Do we need minimum requirements for cybersecurity knowledge in sales?

    Thanks to our podcast sponsors, Devo, Eclypsium & NetSPI

    Devo replaces traditional SIEMs with a real-time security data platform.

    Devo’s integrated platform serves as the foundation of your security operations and includes data-powered SIEM, SOAR, and UEBA. AI and intelligent automation help your SOC work faster and smarter so you can make the right decisions in real-time.

    Eclypsium is helping enterprises and government agencies mitigate risks to their infrastructure from complex technology supply chains. Our cloud-based and on-premises platform provides digital supply chain security for software, firmware and hardware in enterprise infrastructure. Get started today at eclypsium.com/spark.

    NetSPI ASM continuously scans your external perimeter to identify, inventory, and reduce risk to both known and unknown assets. It blends scanning methodology with our consultants' human intelligence to identify previously undiscovered data sources and vulnerabilities so you can remediate what matters most.

    Show more Show less
    44 mins