
Defense in Depth
Defense in Depth promises clear talk on cybersecurity’s most controversial and confusing debates. Once a week we choose one controversial and popular cybersecurity debate and use the InfoSec community’s insights to lead our discussion.
Latest episodes

Apr 4, 2024 • 31min
Onboarding Security Professionals
Former CISO, Paul Connelly, discusses the crucial role of onboarding new cybersecurity talent, emphasizing the need for effective training and avoiding common mistakes. Strategies include fostering engagement, cross-team collaboration, and early exposure to different departments to create a positive onboarding experience.

Mar 28, 2024 • 29min
How to Improve Your Relationship With Your Boss
Jerry Davis, division director for cyber defense at Truist Bank, discusses the importance of building relationships with your boss to advance your cyber career. Topics include developing soft skills, effective communication strategies, setting clear expectations, and mastering leadership dynamics for success in the workplace.

5 snips
Mar 21, 2024 • 28min
Improving the Responsiveness of Your SOC
Exploring the challenges of integrating new tools in a SOC and the importance of readiness measures. Discussing the shift from past events to current activities, focusing on speed and measurable outcomes. Highlighting the role of Security Orchestration in boosting SOC efficiency. Delving into the shift towards behavioral monitoring in cloud environments. Reflecting on the ineffectiveness of current security measures and the need for proactive actions.

Mar 14, 2024 • 29min
The Demand for Affordable Blue Team Training
Exploring the high cost of blue team training compared to free red team education, discussing the impact on cybersecurity talent shortage. Highlighting the importance of self-learning and versatile tools in cybersecurity defense. Emphasizing the need for collaboration between red and blue teams, and the evolving threats in the cybersecurity landscape.

Mar 7, 2024 • 33min
Why are CISOs Excluded from Executive Leadership?
Exploring the absence of CISOs in executive leadership, challenges faced by CISOs in Fortune 100 companies, importance of clear guidelines and compliance, CISOs' role in disclosure decision-making post-security breaches, and contrasting perspectives on privacy and security prioritization.

Feb 29, 2024 • 31min
What Is Your SOC's Single Search of Truth?
Exploring the limitations of consolidating data from various sources with a single pane of glass concept. Discussing the challenges of centralized data analysis in cybersecurity operations. Introduction of Query Federated Search as a solution for managing security data sources. Emphasizing the importance of understanding and leveraging security data efficiently in SOC operations.

Feb 22, 2024 • 35min
When Is Data an Asset and When Is It a Liability?
The podcast discusses the balance between data being an asset and a liability for organizations, the risks of data collection, and the importance of data minimization. It explores privacy laws, lawsuits targeting tech companies, and ethical considerations surrounding data collection. The Electronic Frontier Foundation emphasizes the significance of minimizing data collection upfront for better privacy and security.

11 snips
Feb 15, 2024 • 34min
Tracking Anomalous Behaviors of Legitimate Identities
Adam Koblentz, field CTO at Reveal Security, discusses monitoring anomalous behavior of users, understanding threat actors in networks, and the role of AI-based tools. They highlight the importance of context in anomaly detection, tracking past activities, and strong multifactor authentication. The chapter emphasizes the significance of anomaly detection and user profiling, with a mention of sponsor Reveal Security as a helpful resource.

4 snips
Feb 8, 2024 • 32min
Why Do Cybersecurity Startups Fail?
Guest Mike Levin, deputy CISO, 3M, discusses the challenges faced by cybersecurity startups, including understanding the market and customer needs. The importance of integration and coexistence of cybersecurity products with existing ones is emphasized. Incorporating customer feedback and listening to the market are key to building a successful cybersecurity startup.

Feb 1, 2024 • 34min
Is "Compliance Doesn't Equal Security" a Pointless Argument?
Derek Fisher, Executive director of product security at JPMorgan, discusses the significance of compliance in a security program and the need to go beyond minimum standards. The podcast explores the difference between compliance and security, emphasizing compliance as the minimum viable security. It also highlights the importance of compliance in the banking industry and the collaboration within the security industry. The episode concludes with a mention of sponsor Reveal Security and a discussion about the benefits of LinkedIn.
Remember Everything You Learn from Podcasts
Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.