
Caffeinated Risk
The monthly podcast for security professionals, by security professionals.Two self proclaimed grumpy security professionals talk security risk, how they’ve managed it in the past and forward looking discussions with guests working in information security and risk management.
Latest episodes

May 19, 2022 • 32min
Strategies for meeting the cyber skill set challenge with Martin Dinel
Exploring strategies for sourcing and retaining cybersecurity talent in Alberta, transitioning from gear-centric to skill-focused cybersecurity, addressing challenges in hiring and retaining specialists in the public sector, building a strong cyber workforce through comprehensive programs, and discussing collaboration for progress in cybersecurity training.

Apr 21, 2022 • 33min
Risk management in the cloud with Illena Armstrong
Exploring cloud risk management challenges, shared accountability in cloud services, evolving attitudes towards cloud services during the pandemic, and the evolution of cybersecurity roles and leadership in organizations

Mar 17, 2022 • 33min
Cyber Crime and Risk Management Strategies with Cara Wolf
Cara Wolf discusses Canadian tech industry innovation, drawing leadership attention to cyber security. Exploring fraud in airlines, cybersecurity challenges, fostering innovation, embracing diversity in cybersecurity.

Feb 16, 2022 • 33min
Continuous Authentication and Risk Management with Ian Paterson
Ian Paterson, CEO of Plurilock, discusses continuous authentication, zero trust models, Canadian startups, talent strengths in STEM, behavior-based cybersecurity, defense strategies, risk management dynamics, and the importance of ongoing risk assessment in a coffee-infused dialogue.

Feb 3, 2022 • 6min
Castles and Network Management with Winn Schwartau
Exploring the evolution of network asset management post-2007 and the challenges it brings. Drawing parallels between network management and medieval castles to enhance security and streamline access.

Jan 20, 2022 • 7min
Unpacking the Security Value Chain - Dave Tyson
Exploring where security can add value in business operations, preventing value loss, and enhancing competitiveness. Discussing a cyber incident involving thwarting a threat actor selling SCADA app kit, highlighting the importance of collaboration between security and business for success.

Dec 16, 2021 • 34min
Innovation and Influence
Comparing and contrasting risk management in various areas, including beyond cyber threats. Discussing the complexities of navigating through uncertainty and human behavior in security. Offering suggestions on influencing action despite competing agendas within organizations.

4 snips
Nov 18, 2021 • 33min
Applying Scientific Principles to Risk Management - With Doug Millward
Exploring the integration of scientific principles in risk management with Doug Millward, a computer scientist sharing insights on cyber security evolution from the 1970's to current threat landscape. The discussion delves into applying data-driven assessments, biases in product advertising, and transitioning to composable systems in cloud technology. The chapter ends with gratitude for audience support and anticipation for future episodes.

Oct 21, 2021 • 31min
Risk and Kinetic Consequences - with Paul Smith
Skilled penetration testers are some of the more specialized people within the information security industry. When it comes to safely testing kinetic systems the pool of talented ethical hackers shrinks again but does include Paul Smith who has written a brand new book on the subject. An ICS security specialist before it was a recognized specialty, Paul Smith has been a field operator, security tester, product manager, ICS vulnerability researcher and more. This episode explores risk consideration when impacts are measured in environmental damage and human life rather than records in a database. Mr. Smith's new book, "Pentesting Industrial Control Systems: An ethical hacker's guide to analyzing, compromising, mitigating and securing industrial processes" , will be released November 9th 2021.

Sep 16, 2021 • 31min
Privacy Engineering, Manifesto & Beyond with Michelle Finneran Dennedy
Explore privacy engineering, challenges of policy implementation, security professionals' practical approach, translating user needs, leadership in regulations, and balancing data collection with privacy concerns in a lively discussion with Michelle Finneran Dennedy on privacy and security.