

Defense in Depth
David Spark, Steve Zalewski, Geoff Belknap
Defense in Depth promises clear talk on cybersecurity’s most controversial and confusing debates. Once a week we choose one controversial and popular cybersecurity debate and use the InfoSec community’s insights to lead our discussion.
Episodes
Mentioned books

13 snips
Feb 27, 2025 • 32min
Are CISOs Struggling to Get Respect?
Lee Parrish, CISO at Newell Brands and author, joins David Tyburski, CISO at Wynn Resorts, to discuss the unique challenges facing CISOs today. They delve into the importance of fostering a strong security culture within organizations and the need for clear communication with boards. The conversation emphasizes empowering non-cyber staff through innovative programs and strengthening relationships to enhance cybersecurity governance. Their insights reveal how strategic engagement can elevate cybersecurity’s importance in corporate discussions.

11 snips
Feb 20, 2025 • 29min
Is Platformization Vs Best-of-Breed a False Dichotomy?
Elad Koren, VP of Product Management for Cortex Cloud at Palo Alto Networks, brings a wealth of expertise in cloud security. He dives into the ongoing debate of platformization versus best-of-breed solutions, challenging the simplistic views often held. Topics include the critical role of context in decision-making, the urgent security challenges faced by leaders, and the necessity of balancing budgets with effective purchasing. Koren emphasizes the importance of understanding organizational needs and the value of integrated security strategies.

12 snips
Feb 13, 2025 • 30min
Protecting Your Backups from Ransomware
DJ Schleen, a former distinguished security architect at Yahoo, and Heath Renfrow, co-founder of Phoenix 24 specializing in ransomware recovery, bring valuable insights on protecting backups. They discuss the rising threats of ransomware and the need for proactive backup strategies. The duo emphasizes the importance of rigorous testing and collaboration in improving data resilience. They also delve into real-world case studies, highlighting common pitfalls organizations face and the necessity for robust recovery solutions to combat cyber threats effectively.

Feb 6, 2025 • 25min
Can a Security Program Ever Reach Maintenance Mode?
Andrew Wilder, CISO at Vetcor, offers a wealth of knowledge in cybersecurity risk management. The conversation centers on the complexities of achieving 'maintenance mode' in security programs. Wilder discusses the balance between proactive measures and optimizing existing tools while navigating organizational growth. He emphasizes the importance of continuous improvement over merely shifting to maintenance mode, highlighting the necessity for effective incident response and ROI assessment in security investments. Wilder also touches on the evolving role of CISOs in business alignment.

22 snips
Jan 29, 2025 • 26min
The Hardest Problems in Security Aren't "Security Problems"
Sneha Parmar, an Information Security Officer at Lufthansa Group Digital Hangar, discusses the importance of viewing cybersecurity as a collective responsibility. She emphasizes the critical role of foundational practices like asset inventory and maintenance, arguing that overlooking these can lead to vulnerabilities. Sneha highlights how understanding organizational assets and fostering accountability can enhance security measures. The conversation also stresses that prioritizing operational discipline is key to building a resilient cybersecurity posture.

26 snips
Jan 23, 2025 • 29min
If and When Should a CISO Have a Long Term Security Plan?
Mike Johnson, CISO of Rivian, and Gaurav Kapil, CISO of Bread Financial, dive deep into the necessity of long-term cybersecurity strategies. They discuss how new CISOs can balance immediate pressures with strategic planning. The conversation highlights the importance of having a flexible vision that adapts to evolving threats. Effective communication with C-suite executives is emphasized as vital for aligning cybersecurity goals. They also stress the indispensable nature of planning, even as strategies must adjust in a dynamic landscape.

Jan 16, 2025 • 34min
Do We Want CISOs Dictating How Salespeople Should Engage?
All links and images for this episode can be found on CISO Series. Check out this post by Marc Ashworth, CISO at First Bank for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Shawn Bowen, vp, deputy CISO - Gaming, Microsoft. Joining us is Ken Athanasiou, CISO, VF Corporation. In this episode: Frustration is a two-way street Sales is data driven Give customers the tools they need Start a conversation Thanks to our podcast sponsor, Noma Security Secure your entire Data & AI Lifecycle—from development to production and classic data engineering to GenAI. Noma’s full-lifecycle platform delivers seamless protection against risks like misconfigured data pipelines, malicious models, and adversarial AI attacks, empowering AppSec teams with complete visibility, security, and compliance—without disrupting data and AI teams’ workflows.

10 snips
Jan 9, 2025 • 30min
Is AI Benefiting Attackers or Defenders?
Rob Allen, Chief Product Officer at ThreatLocker, dives into the intricate dance between AI and cybersecurity. He discusses the promise of large language models, emphasizing their potential to aid defenders while acknowledging the risks they pose when leveraged by attackers. The conversation highlights the necessity of strong security fundamentals, handling AI's dual nature carefully. Allen also addresses how AI can impact trust and the critical need for discernment in an age of deep fakes and misinformation.

Jan 2, 2025 • 30min
CISOs DO Own the Risk
All links and images for this episode can be found on CISO Series. Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Ross Young, CISO-in-residence, Team8, and Jeroen Schipper, CISO, Gemeente Den Haag. In this episode: Creating authority Don’t reinvent the wheel Accountable for quality Make the distinction clear Thanks to our podcast sponsor, Fenix24 You’ve invested in cybersecurity, but can your business recover when it counts? The Securitas Summa program from the Conversant Group combines resistance, managed protection, and rapid recovery to minimize downtime and restore operations faster than anyone else. Resilience isn’t optional. Click to see how it works.

4 snips
Dec 12, 2024 • 28min
How Can We Fix Alert Fatigue?
All links and images for this episode can be found on CISO Series. Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Itai Tevet, CEO, Intezer. In this episode: Build for what you can handle Rethinking alerts Building trust into your system Seeing the bigger picture Thanks to our podcast sponsor, Intezer Intezer’s AI-driven solution automates alert triage and investigations, cutting through the noise to highlight serious threats. By integrating with your security tools, it escalates only 4% of alerts for fast remediation, helping SOC teams focus on what matters. Learn more at intezer.com today!