Life of a CISO with Dr. Eric Cole

Dr. Eric Cole
undefined
Jun 12, 2025 • 35min

From Pen Testing to Purpose: Jane Frankland on Cyber, Burnout, & Reinvention

In this special episode of Life of a CISO, I sit down with the brilliant Jane Frankland, MBE—an internationally recognized thought leader in cybersecurity with over 28 years of experience. Jane shares her unexpected journey into the field, starting not from a tech background but from art and design. Her curiosity and drive led her to co-found one of the earliest penetration testing consultancies, long before the term "cybersecurity" became mainstream. Together, we dive into how the industry has evolved, why penetration testing has become commoditized, and why it's no longer enough to offer just technical solutions—true value now comes from insight, strategy, and resilience.   Jane also offers powerful reflections on the burnout many CISOs face today and why so many are leaving traditional roles to launch their own consultancies or step into virtual CISO models. We discuss what it really means to build a business in today’s climate, the importance of defining your unique value, and why small businesses are an underrated opportunity in the cyber space. From vendor strategy to shifting away from limiting beliefs, Jane brings a fresh, honest, and empowering perspective that challenges the status quo. Whether you're building your career or launching your own venture, this episode is full of clarity and inspiration for the next step in your cyber journey.  
undefined
Jun 5, 2025 • 32min

Breaking the IT Inertia with Google Cloud's Dr. Anton Chuvakin

In this episode of Life of a CISO, Dr. Eric Cole reconnects with longtime friend and cybersecurity legend Dr. Anton Chuvakin, whom he has known for over 25 years. The conversation opens with reflections on their decades-long professional journey and transitions into a deep dive into Anton’s current work at Google Cloud’s Office of the CISO. Anton shares how his team supports secure cloud and AI adoption—not as traditional field CISOs focused on sales—but as strategic advisors and researchers helping clients understand and implement Google’s advanced security models. The discussion spotlights Google’s internal use of Zero Trust architecture, highlighting how Google eliminated the need for VPNs over a decade ago. Anton explains how this approach—initially pioneered through Google’s BeyondCorp—combines stronger security with greater usability, a rare balance in cybersecurity. Dr. Cole presses into why more companies haven’t adopted Zero Trust, prompting Anton to emphasize the power of organizational inertia. Drawing from his years at Gartner, Anton notes that despite the proven benefits, many enterprises resist change due to legacy systems and mindset barriers. This episode offers a compelling look at the evolving landscape of enterprise security and the importance of embracing innovation over outdated habits.  
undefined
May 29, 2025 • 35min

Breaking Into Cybersecurity and Future Trends with Henrik Parkkinen

In this episode of Life of a CISO, Dr. Eric Cole interviews Hendrik Parkkinen, a seasoned cybersecurity expert from Sweden with over 20 years of experience, mostly in consulting and security strategy. They discuss Henrik’s journey into cybersecurity, emphasizing how passion and curiosity play a crucial role in succeeding in the field. Henrik shares how he transitioned from studying economics to cybersecurity after a recommendation from his mother and how he fell in love with the subject through a 12-month training program. Both Eric and Henrik highlight the importance of loving the work rather than just chasing money, since cybersecurity demands ongoing learning and commitment beyond regular hours. They also discuss practical advice for newcomers: be curious, explore various domains within cybersecurity, and don’t be afraid to pivot if something doesn’t fit. With the rise of accessible and often free learning resources online, breaking into the field is more feasible than ever, but focus and completing courses is essential. When it comes to certifications, Henrik believes they serve as useful entry points or validation badges, especially for HR filters, but experience and mastery are ultimately more important. Certifications should be viewed as part of a broader learning process, not an end in themselves.  
undefined
May 22, 2025 • 32min

Alignment

In this new episode of Life of a CISO, Dr. Eric Cole opens with one of his most powerful guiding principles: “Let data drive decisions, not emotions.” Drawing from his experiences traveling and meeting with top executives, he emphasizes the importance of making decisions based on reliable data rather than emotional impulses. He challenges listeners to ask themselves whether they have enough information to make an informed choice—not perfect information, but sufficient insight to move forward. When we delay decisions out of fear or uncertainty, it’s often because we lack confidence due to missing data. Dr. Cole encourages action: if you don’t have enough data, go get it. He then introduces his second foundational principle: “Smart people know the right answers; brilliant people ask the right questions.” These two mantras form the core of what it means to be a world-class CISO. But Dr. Cole takes it even further, revealing that the root of most professional frustration stems from a lack of alignment—whether it’s misalignment with your goals, your team, or the organization itself. He draws parallels between business alignment and physical alignment in cars or our bodies, reinforcing that clarity of purpose and alignment of actions are essential for not only being effective, but also reducing stress. Whether you’re a CISO or not, these lessons apply to every area of life.  
undefined
May 15, 2025 • 32min

CISO Blind Spots

In this episode of Life of a CISO, Dr. Eric Cole shines a spotlight on a critical blind spot that many Chief Information Security Officers overlook: legal liability. While CISOs are often highly skilled and technically knowledgeable, it’s what they don’t know—particularly about their legal exposure—that can put them at serious risk. Dr. Cole explains that many CISOs hold the title of “chief” without realizing they may not officially be corporate officers, and that distinction matters. If you are considered a true officer of the company, you may be personally liable for failures or breaches, even if you weren't the root cause. He urges CISOs to ask the right questions during negotiations, ensure they understand their official role, and protect themselves with legal counsel and proper insurance coverage. He goes on to emphasize the importance of understanding how communication becomes evidence at the executive level. In today’s digital world, emails and text messages are no longer just conversations—they are legal records that can be used for or against you. Dr. Cole discusses how even a lack of written documentation can lead to lawsuits or termination if it's perceived that a CISO failed to inform the board about a critical risk. However, over-documenting can also backfire by making colleagues uncomfortable or wary. This delicate balance between transparency and discretion is a key leadership skill every CISO must develop. Ultimately, this episode is a wake-up call to every cybersecurity leader: the higher you rise, the more you must be aware of the legal and personal implications of your role.  
undefined
May 8, 2025 • 33min

AI Risks

In this episode of Life of a CISO, Dr. Eric Cole dives deep into the dominating force of 2025: artificial intelligence. While AI is everywhere—embedded in nearly every conversation and technology—the real concern, he explains, isn’t just about its capabilities but the risks it brings, especially in cybersecurity and data privacy. Dr. Cole breaks AI down into its two primary types: machine learning, which relies on data sets, and expert systems, which mimic expert decision-making through logical rules. He shares how AI isn’t new, recounting his own early work building simple expert systems back in college, but warns that today’s AI is only as good—or as dangerous—as the data it consumes. Dr. Cole emphasizes that data is the real power behind AI, not the algorithms. Using TikTok as an example, he highlights how data collected over years can predict behaviors and influence markets, creating national security and privacy concerns. He also discusses why big players like Amazon might seek access to such rich behavioral data to maintain dominance in e-commerce. Drawing attention to the eerie accuracy of modern predictive systems, Dr. Cole calls on CISOs and security professionals to take responsibility: every interaction with AI is feeding it data, and that data needs to be protected. He urges leaders to ask tough questions about where their data goes, how it's used, and whether they are unknowingly contributing to systems that could expose sensitive information.  
undefined
May 1, 2025 • 28min

Blindspots

In this powerful episode of Life of a CISO, Dr. Eric Cole opens by highlighting a key success principle: even the world’s top performers — whether in sports, business, or entertainment — rely on coaches to help them spot their blind spots. Drawing from his deep experience coaching CISOs, Dr. Cole shares that cybersecurity leaders are no different. They often miss critical areas simply because they're too focused on day-to-day operations. He emphasizes that one of the most common blind spots for CISOs is the unrealistic pursuit of 100% security, which simply doesn’t exist. As Dr. Cole reminds us, every added functionality in a business decreases security — and breaches are not a question of if but when. The episode dives deep into the mindset shift every CISO must make: embracing the breach. This doesn’t mean accepting failure, but rather committing to early detection, fast response, and minimizing business impact when an incident occurs. Dr. Cole stresses that a CISO’s survival depends on aligning with executives early, clearly communicating that breaches are inevitable, and setting realistic expectations. Without that alignment, companies often fire the CISO after a breach — not because of the breach itself, but because of failed communication. To prevent this, Dr. Cole recommends that CISOs regularly update executives with simple, non-technical risk reports that show the likelihood, potential cost, and status of key security threats. By turning security into a transparent business conversation, CISOs can transform from scapegoats to trusted advisors — even in the face of attacks.  
undefined
Apr 24, 2025 • 32min

What You Must Master This Year

In this episode of Life of a CISO, Dr. Eric Cole kicks off the 2025 CISO Survival Guide Series, diving deep into the evolving demands on security leaders in today’s fast-moving landscape. With shifting tides in government, corporate trends, and technology, Dr. Cole emphasizes the urgent need for CISOs to master AI governance and threat modeling—not from a coding or development angle, but from a strategic oversight perspective. He shares personal stories from his early days working with neural networks in national security, highlighting how today’s cybersecurity environment finally has the historical data to make AI effective in predicting threats. But with AI now being widely used to create work products, Dr. Cole challenges security leaders to think critically about legal, ethical, and governance implications in the workplace. He also introduces the second major pillar of this survival guide: executive communication. Dr. Cole points out a major gap in how CISOs are treated compared to other C-level executives, and he urges cybersecurity leaders to analyze their org charts and step up their executive presence. If CISOs want a seat at the table, they must learn to speak the language of the boardroom and operate at the same strategic level as their C-suite peers. This episode sets the stage for a multi-part deep dive into the five key areas every CISO must master to survive—and thrive—in 2025 and beyond.  
undefined
Apr 17, 2025 • 26min

Balancing Risk and Innovation

In the latest episode of Life of a CISO, Dr. Eric Cole kicks things off with an empowering reminder that it's the little things that often make the biggest difference. He challenges listeners to adopt a simple but powerful habit—repeat the affirmation “I am a world-class CISO” at least ten times a day. Why? Because repetition trains the mind to believe. Dr. Cole explains how our brains are goal-achieving machines, and when we’re vague about what we want, we might get results we didn’t intend. So instead of saying, “I want to be a CISO,” he urges us to define exactly what that means and aim higher: world-class. This episode dives into the power of affirmations, intention, and mindset. Dr. Cole shares how creating and regularly reviewing a detailed written vision of your future self as a world-class CISO can help anchor that affirmation in reality. The idea is to replace negative internal voices with empowering declarations and make these part of your daily rhythm—while brushing your teeth, driving, or walking between meetings. And once that belief is solidified, you can shift your focus to new growth areas, aligning your “I am” statements with your weekly, monthly, or yearly goals. It’s a masterclass in mental conditioning, identity shaping, and becoming the version of yourself you truly aspire to be.  
undefined
Apr 10, 2025 • 30min

Data

In this powerful new episode of Life of a CISO, Dr. Eric Cole issues a wake-up call to everyone living in the digital age: we are in the middle of a cyber war, and most people are walking around completely unaware. He shares real-life stories of family and friends falling victim to text scams and phishing attacks, driving home the point that if these attacks weren’t working, they wouldn’t keep happening. Dr. Cole stresses the need to shift from a peacetime mentality to a wartime mindset—especially online. Just as we wouldn’t hand out personal information to a stranger on the street, we must stop doing so digitally. The key is education—training those around us, especially the less tech-savvy, to recognize and avoid cyber traps. He then transitions into the responsibilities of a world-class chief information security officer, focusing on one core truth: you can’t protect what you don’t know. In a world overflowing with data—from laptops to phones to cloud platforms—most organizations can’t answer two critical questions: What is your sensitive data, and where is it located? Dr. Cole warns that if we lose track of our data, we lose control over it entirely. With companies going bankrupt and selling off systems that store sensitive personal data, he raises an urgent concern—who really owns your information? It’s time to take accountability, regain control of our data, and secure our digital future.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app