

CISO Series Podcast
David Spark, Mike Johnson, and Andy Ellis
Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.
Episodes
Mentioned books

Jun 3, 2025 • 45min
AI Isn't Going to Take Your Job, It's Going to Eliminate It! (LIVE at BSidesSF)
All images and links can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), partner, YL Ventures. Joining us is Alexandra Landegger, global head of cyber strategy & transformation, RTX. In this episode: A cybersecurity fast-track? When Ambition Becomes a Liability Giving the CVE Program the Credit It Deserves Elevating human cyber talent with AI Huge thanks to our sponsors, Nudge Security, SecurityScorecard, and Vanta Take control of SaaS security and AI governance with Nudge Security. Start a free trial today and get a full inventory of all SaaS and GenAI accounts in minutes along with risk insights and automation to help you quickly improve your security posture. Get started here: nudgesecurity.com/cisoseries Third-party risk doesn't stop at monitoring. SecurityScorecard delivers real-time detection and response across your supply chain—helping you fix vulnerabilities before they become breaches. Empower your team with expert-driven remediation, continuous vendor oversight, and board-ready insights that drive results. Automate, centralize, & scale your GRC program with Vanta Vanta's Trust Management Platform automates key areas of your GRC program—including compliance, internal and third-party risk, and customer trust—and streamlines the way you gather and manage information. And the impact is real: A recent IDC analysis found that compliance teams using Vanta are 129% more productive. Get started at Vanta.com/ciso.

May 27, 2025 • 34min
I Can't Choose. I Love All My Assets Equally.
All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), partner, YL Ventures. Joining us is Tim Jacobs, vp, CISO, Commonwealth Care Alliance. In this episode: Starting from zero Prepare for decisive decisions Working back from unacceptable Discovering inefficiencies A huge thanks to our sponsor, ThreatLocker ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

May 20, 2025 • 34min
Why Learn Security Fundamentals When We Could Just Chase Our Tails?
All links and images for this episode can be found on CISO Series. I host this week's episode, David Spark (@dspark), producer of CISO Series and Jesse Whaley, CISO, Amtrak. Joining them is their guest Vaughn Hazen, CISO, CN. In this episode: The classics endure The rules of the rail "Prove It. With data." It's all just software A huge thanks to our sponsor, Doppel Doppel is the first social engineering defense platform built to dismantle deception at the source. It uses AI and infrastructure correlation to detect, link, and disrupt impersonation campaigns before they spread - protecting brands, executives, and employees while turning every threat into action that strengthens defenses across a shared intelligence network. Learn more at https://www.doppel.com/platform

May 13, 2025 • 42min
I'm Not Looking Down at You, I'm Looking Down at What You're Doing
Saket Modi, Co-founder and CEO of SAFE Security, dives deep into the intersection of AI and cybersecurity. He discusses the essential role of AI in managing cyber risks and emphasizes the need for robust human oversight. The conversation highlights the importance of adopting a holistic approach to third-party risk management while navigating the ethical dilemmas of IT management. Modi also shares innovative strategies and tools designed to improve vendor assessments and ensure AI remains a support system rather than an autonomous actor.

May 6, 2025 • 46min
They're Not AI Mistakes, They're Happy Little Incidents
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark, producer of CISO Series, and Andy Ellis, partner of YL Ventures. Their sponsored guest is Jadee Hanson, CISO of Vanta. In this episode: Find a partner to work with Fixing the root of burnout The limitations of human vigilance Balancing openness and control Thanks to our sponsor, Vanta. Automate, centralize, & scale your GRC program with Vanta Vanta's Trust Management Platform automates key areas of your GRC program—including compliance, internal and third-party risk, and customer trust—and streamlines the way you gather and manage information. And the impact is real: A recent IDC analysis found that compliance teams using Vanta are 129% more productive. Get started at Vanta.com/ciso.

Apr 29, 2025 • 40min
Get ALL the Challenges of Cybersecurity AND Fewer Resources
Charles Blauner, an operating partner at Crosspoint Capital and cybersecurity expert, discusses the evolving landscape of cybersecurity. He highlights the challenges CISOs face, from managing external scrutiny to navigating complex reporting structures. Blauner emphasizes the need for innovative talent strategies to recruit local talent and improve community security. The conversation also touches on access control risks and the potential of government placements in the private sector, positioning cybersecurity as a dynamic field requiring constant adaptation.

Apr 22, 2025 • 42min
Data Minimization Means We Don't Tell You What We're Collecting
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark, producer of CISO Series, and Andy Ellis, partner, YL Ventures. Joining us is Mandy Huth, svp, CISO, Ultra Clean Technology. In this episode: Start with good defaults Building talent bridges Don't forget the humans Differentiating with privacy Automate, centralize, & scale your GRC program with Vanta Vanta's Trust Management Platform automates key areas of your GRC program—including compliance, internal and third-party risk, and customer trust—and streamlines the way you gather and manage information. And the impact is real: A recent IDC analysis found that compliance teams using Vanta are 129% more productive. Get started at Vanta.com/ciso.

Apr 15, 2025 • 41min
Welcome to Cybersecurity: Where Everything Is Made Up and the Points Don't Matter
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis, partner, YL Ventures. Joining us is Mike D'Arezzo, executive director of infosec and GRC, Wellstar Health Systems. In this episode: The shift left myth Reconsidering CISO evaluations The power of "how" Building bridges Huge thanks to our sponsor, ThreatLocker ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

Apr 8, 2025 • 39min
With AI, Don't Think Like a Hacker, Think Like the Whole of Society
Nathan Hunstad, Director of Security at Vanta, shares insights on navigating the complex landscape of AI and security. He emphasizes the need to rethink adversaries, including everyday users, to enhance AI deployment. Discussions delve into the importance of SOC 2 compliance for startups while treating generative AI like any other application. Hunstad also highlights building a robust security foundation beyond mere certifications and the necessity of strong leadership and teamwork in tackling vulnerability management.

Apr 1, 2025 • 45min
This Security Control Is So Good We Don't Even Have to Turn It On (LIVE in Clearwater, FL)
Christina Shannon, CIO of KIK Consumer Products, and Jim Bowie, CISO of Tampa General Hospital, discuss vital cybersecurity strategies. They highlight the need for continuous security awareness training over traditional compliance sessions. The duo explores the balance between high-pressure environments and team well-being. As they dissect the vulnerabilities of weak passwords versus phishing, they also share humorous incidents from training, emphasizing a collaborative and engaging approach to fostering a strong security culture.


