

CISO Series Podcast
David Spark, Mike Johnson, and Andy Ellis
Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.
Episodes
Mentioned books

Jan 14, 2025 • 37min
I Support Open Source as Long as I Don't Have to Invest in It
Brett Perry, CISO at Dot Foods, dives into the evolving landscape of cybersecurity. He discusses the challenges of managing remote work and the importance of on-site training for young employees. The conversation covers the implications of Managed Detection and Response (MDR) services on pricing and competition, as well as the pressing issue of technical debt in security tools. Additionally, Brett shares insights on effective retention strategies, the balance between automation and expertise, and the critical need for mentorship among aspiring CISOs.

Jan 7, 2025 • 39min
Ewww! How Long Has This Router Been in the Fridge?
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), partner, YL Ventures. Joining us is Yabing Wang, VP and CISO, Justworks. In this episode: Building a path to action Cracking the EOL conundrum The burning platform question Uncertainty is our only constant Thanks to our podcast sponsor, Entro! Reclaim control of your non-human identities with Entro Security! Our platform securely manages non-human identities and secrets throughout their lifecycle. Detect and prevent unusual activity before it becomes a threat. Trust Entro to safeguard your non-human identities in today's complex digital ecosystem.

Dec 17, 2024 • 38min
Why Bother Helping Users When We Can Complain About Them?
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is our sponsored guest Daniel Daraban, senior director of product management, Bitdefender. In this episode: Practice makes perfect Shaming doesn't help anyone Cybersecurity is a flat circle Building the bridge Thanks to our podcast sponsor, Bitdefender! Enterprise-grade cybersecurity without complexity. Backed by extensive research from hundreds of experts in Bitdefender Labs and consistently top-rated in independent tests, Bitdefender GravityZone platform provides multi-layered prevention, protection, detection, and response capabilities, including managed security services. Learn more at Bitdefender.com.

4 snips
Dec 10, 2024 • 38min
Can't Our Employees Just Go Back to Stealing Pens?
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is our sponsored guest, Itzik Alvas, co-founder and CEO, Entro. In this episode: What to expect when you're offboarding The threats are coming from inside the organization The risk of stale identities Working backward to risk Thanks to our podcast sponsor, Entro! Reclaim control of your non-human identities with Entro Security! Our platform securely manages non-human identities and secrets throughout their lifecycle. Detect and prevent unusual activity before it becomes a threat. Trust Entro to safeguard your non-human identities in today's complex digital ecosystem.

Dec 3, 2024 • 35min
We Take Software Security Seriously, As Long As It Ships on Time
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is our sponsored guest Jeremy Epling, chief product officer, Vanta. In this episode: What is the future of cybersecurity? Designing the outcomes we want The promise and peril of AI Is open-source open to more threats? Thanks to our podcast sponsor, Vanta! Say goodbye to spreadsheets and screenshots. Vanta automates evidence collection needed for audits with over 350 integrations—giving you continuous visibility into your compliance status. And with cross-mapped controls across 30 frameworks, you'll streamline compliance— and never duplicate your efforts. Learn more at Vanta.com.

Nov 26, 2024 • 41min
Aww, Your Cybersecurity Concerns Are So Adorable (LIVE in La Jolla)
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Gary Hayslip, CISO, Softbank Investment Advisors. Joining us is Keith McCartney, VP, Security and IT, DNAnexus. In this episode: Closing the Credibility Gap Clarifying the Role of Security Engineering Building Resilience at Scale AI Frameworks and Cybersecurity Thanks to our podcast sponsor, Entro! Reclaim control of your non-human identities with Entro Security! Our platform securely manages non-human identities and secrets throughout their lifecycle. Detect and prevent unusual activity before it becomes a threat. Trust Entro to safeguard your non-human identities in today's complex digital ecosystem.

Nov 19, 2024 • 40min
Once You Show Me Your Diploma, I'll Explain Why We Don't Gatekeep
Jimmy Benoit, VP of Cybersecurity at PBS, shares his expertise on early cybersecurity education and workforce development. He discusses the importance of engaging younger generations through creative methods like gamification and interactive events. Benoit critiques traditional training approaches, advocating for skills-based hiring and inclusivity in cybersecurity. He also highlights the need for meaningful learning experiences beyond mere certifications, emphasizing how effective leadership can enhance team productivity and engagement.

Nov 12, 2024 • 46min
Wait, We Can Prioritize Data Privacy Before an Incident? (LIVE at Stanford University)
This discussion dives into the importance of data privacy and how to prioritize it before incidents occur. A fascinating look at zero trust security reveals its challenges and benefits. The impact of AI on job security ignites lively debate. Attendees share skepticism about the role of CISOs, highlighting their unique position in today's cybersecurity landscape. Lessons from past security missteps underscore the need for collaboration and effective communication among key stakeholders.

16 snips
Nov 5, 2024 • 41min
Luckily, We Haven't Had to Adapt to Any New Technologies Before AI
Jadee Hanson, CISO at Vanta, shares her insights on the future of cybersecurity. She discusses the exciting yet challenging landscape of AI integration in workplaces and the necessary transparency for effective adoption. The conversation highlights the complexities of navigating compliance in the defense sector, including CMMC 2.0 requirements and supply chain security. Jadee also emphasizes the importance of multi-factor authentication in banking, stressing the need for robust measures to protect sensitive data from breaches.

17 snips
Oct 29, 2024 • 35min
We Need to Hire a Unicorn But We Only Have Budget for a Donkey
Jason Shockey, CISO at Cenlar FSB, brings his military and intelligence expertise to the forefront of cybersecurity discussions. He emphasizes enhancing communication within Security Operations Centers to improve team dynamics. Shockey advocates for diverse hiring practices that value talent over rigid educational requirements. He also highlights the critical role of training in employee retention and navigates the challenges of crisis management in cybersecurity. His insights blend humor with strategies for effective leadership in this evolving landscape.


