CISO Series Podcast

David Spark, Mike Johnson, and Andy Ellis
undefined
10 snips
Oct 6, 2026 • 44min

Data Is the New Oil, in That It's Useless Until You Refine It

Jake Lorz, Cintas’ vice president of IT and CISO, joins the conversation on security’s identity crisis in an AI-powered workplace. They explore action-centric controls for agentic AI, why AI SOCs must fail safely, and how MFA exceptions can create dangerous account sharing. The discussion also covers data governance, over-permissioned information, institutional memory, and empowering teams without replacing human judgment.
undefined
Sep 29, 2026 • 42min

Mirror, Mirror on the Wall, Who Has the Best Infrastructure of Them All?

All links and images can be found on CISO Series This week's episode is hosted by me, David Spark, the producer of CISO Series, and Geoff Belknap. Joining us is our sponsored guest Ryan Lloyd, chief product officer, GuardSquare. In this episode: Determinism was never the point Every MCP server is an uncontracted vendor Mobile security, the version everyone's tired of hearing Architectural vanity A huge thanks to our sponsor, Guardsquare Guardsquare delivers mobile app security without compromise, providing advanced protections for both Android and iOS apps. From app security testing to code hardening to real-time visibility into the threat landscape, Guardsquare solutions provide enhanced mobile application security from early in the development process through publication. Learn more about how to protect your app at Guardsquare.com.
undefined
12 snips
Sep 22, 2026 • 46min

Our AI Agents Are So Safe and Reliable You Can't Buy Insurance for Them

Aaron Stanley, cybersecurity executive and former dbt Labs security VP, explores the growing challenge of AI agents. They discuss agent identity and ownership, why communication is central to security leadership, the dangers of alert overload, and why insurers struggle to price AI risk. The conversation closes with identity governance and security’s opportunity to help shape AI’s future.
undefined
Sep 21, 2026 • 21min

BONUS EPISODE: Super Cyber Friday Express - Hacking Vendor Selection

All links and images can be found on CISO Series This is a bonus episode of our brand new podcast, Super Cyber Friday Express — a 20-minute highlight version of our live one-hour show we do every available Friday at 1 p.m. Eastern. In this episode, David Spark is joined by Karl Mattson, founder and managing director of Squared Circle Ventures, and Howard Holton, founder and principal analyst at Phronia Counsel LLC, to discuss how your existing environment shapes what you buy next — and whether that's a strategy or just inertia. Watch the full one-hour show at Crowdcast. Subscribe to Super Cyber Friday Express, or any show on CISO Series, at CISOseries.com/subscribe.
undefined
10 snips
Sep 15, 2026 • 44min

We Strongly Value Your Willingness to Accept Less

Gina Ciavaro, a cybersecurity and infrastructure executive and former CISO, explores the realities of security leadership. They discuss prioritizing vulnerabilities, spotting red flags in CISO job postings, and avoiding costly security-tool contracts. The conversation also tackles incident decision rights, executive risk acceptance, and how rapid AI automation can hide architectural decay.
undefined
Sep 8, 2026 • 42min

Backlogs? Where We're Going We Don't Need Backlogs.

All links and images can be found on CISO Series This week's episode is hosted by me, David Spark, producer of CISO Series and Steve Zalewski. Joining us is Varsha Agrawal, head of information security, Prosper Marketplace. In this episode: Lock-in was never about the tech The board wants a green light, not a lesson Time was never the constraint What founders keep getting wrong about security A huge thanks to our sponsor, Vanta No, it's not your imagination. Risk and regulations ARE ramping up—and customers now expect proof of security just to do business. That's why Vanta is a game-changer. Vanta automates your compliance process and brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Companies like Ramp and Writer spend 82% less time on audits with Vanta. That's not just faster compliance—it's more time for growth. Get started at Vanta.com/CISO.
undefined
Sep 1, 2026 • 37min

When Frameworks Stop Being Polite and Start Getting Real

All links and images can be found on CISO Series This week's episode is hosted by me, David Spark, producer of CISO Series and Will Gregorian, CISO, Galileo Medical. Joining us is Ryan Brown, director and head of cybersecurity operations, Children's National Hospital. In this episode: Policy is easy. The exam room isn't. Robotics, Asimov, and the gap before regulation The token bill nobody can explain The 3 AM call is a warning sign A huge thanks to our sponsor, Guardsquare Guardsquare delivers mobile app security without compromise, providing advanced protections for both Android and iOS apps. From app security testing to code hardening to real-time visibility into the threat landscape, Guardsquare solutions provide enhanced mobile application security from early in the development process through publication. Learn more about how to protect your app at Guardsquare.com/CISO.
undefined
4 snips
Aug 25, 2026 • 39min

"Ignorance Is Bliss" Is Our Acceptable Use Policy

Rob Allen, Chief Product Officer at ThreatLocker, a product leader focused on zero trust and access control. He discusses designing controls assuming vulnerabilities exist. He talks about making shadow AI visible and controlled. He covers the Mac vs Windows security debate and hiring for imagination over acronyms.
undefined
Aug 18, 2026 • 38min

Secure by Design. Ignored by Default.

Julie Davila, president of Security Tinkerers and seasoned security leader who builds software factory security frameworks. She explores treating security as a quality discipline. They discuss architecture-driven incidents and why blanket best practices fail. Practical stories cover serverless, automation, compliance realities, ownership tradeoffs, and constraining agents to limit blast radius.
undefined
Aug 11, 2026 • 41min

Why Solve Your Problems When We Can Just Scare You?

Nada Noaman, SVP and CISO at Estée Lauder Companies, security leader in risk management and cloud. They debate AI as aid or hazard for security. They discuss preserving human apprenticeship while automating tasks. They highlight AI agents acting as unmanaged privileged users and argue for collaborative ownership of agent risk. They stress sandboxes, auto-remediation, and team well‑being.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app