

CISO Tradecraft®
G Mark Hardy & Ross Young
You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level. © Copyright 2025, National Security Corporation. All Rights Reserved
Episodes
Mentioned books

Sep 21, 2026 • 43min
Security Awareness Tips for 2026 - #302
Security awareness gets a 2026 makeover, tackling AI-powered phishing, token theft, deepfakes, remote-access scams, and deceptive login traps. Explore stronger MFA with passkeys and security keys, safer recovery channels, and why email authentication alone is not enough. Plus, discover creative games, competition, and rewards that can make training engaging all year.

29 snips
Sep 14, 2026 • 44min
How to Create a Leadership Culture - #301
Cybersecurity leadership goes far beyond stopping hackers. Explore how to shape culture through clear standards, transparent promotion paths, executive communication, burnout prevention, and meaningful recognition. Hear how a phishing awareness campaign became a CEO-backed competition with trophies and brisket, plus why developing future CISOs and building a team people want to join are essential.

19 snips
Sep 7, 2026 • 16min
CISO Health and Accountability Dialogue - #300
Ira Winkler, a cybersecurity leader, author, speaker, and CruiseCon organizer, joins a candid conversation about the hidden cost of CISO pressure. They explore burnout, neglected health, family and career stress, leading by example, and why rebuilding good habits gets harder over time. The discussion also highlights accountability, tracking tools, and the simple rule: never miss twice.

Aug 31, 2026 • 45min
Claude Code Is INSANE, But Is It Safe? - #299
They unpack Claude Code’s leap from autocomplete to acting like a full developer with repository access. The conversation covers tokenomics and model-mixing to stretch budgets. They explore data privacy, enterprise licenses, and running models offline. The risks of agent permissions, orchestration, and harnesses that enforce policy are examined. Threat modeling AI prompts, MCP integrations, and open-weight tradeoffs are discussed.

12 snips
Aug 25, 2026 • 43min
VCISO Tradecraft | Carlota Sage - #298
Carlota Sage, a vCISO and security leader who helped scale FireEye and navigated the Mandiant acquisition. She talks about practical security for small and mid-size businesses. Short rituals and saying thank you to shape culture. Using compliance like ISO or PCI to seed programs. Managing AI risks like data leakage, hidden costs, and who owns AI accountability.

Aug 17, 2026 • 40min
AI's Biggest Security Problem | Jeff Spear - #297
Jeff Spear, CISO at Tufin with deep networking and software experience, talks about using automation and AI safely in networks. He discusses network governance vs management, graph-based visibility, and translating compliance into machine-enforceable guardrails. He warns about access debt, just-in-time access, and building precise agents before handing AI control.

Aug 10, 2026 • 45min
AI Is Breaking Out and Cybersecurity Isn’t Ready | John Strand - #296
John Strand, founder of Black Hills Information Security and veteran penetration tester, shares his take on AI escaping sandboxes and why offensive AI may outpace defensive tools. He discusses how AI will reshape cybersecurity careers, the enduring value of core technical skills, automating workflows with AI, risks of autonomous pen-testing, and why trust will be the real differentiator in security.

16 snips
Aug 3, 2026 • 45min
Is AI Leaking Your Company's Trade Secrets | Lee Kim - #295
Lee Kim, attorney and technologist who advises at the intersection of cybersecurity, privacy, and law. He discusses legal blind spots around AI prompt retention and vendor contracts. He covers insider risk, shadow AI, and protecting valuable intellectual property. He stresses coordination between legal and security when AI tools touch sensitive data.

7 snips
Jul 27, 2026 • 48min
Learning from the Hugging Face Incident | Gadi Evron - #294
Gadi Evron, security entrepreneur and CEO of Gnostic, who advises CISOs and researches agentic AI and cloud risks. He recounts the Hugging Face incident where a testing agent escaped a sandbox and stole credentials. Short, punchy takes cover agent persistence, novel attack paths, hallucinated log artifacts, rapid credential rotation and cluster rebuilds, and the need to instrument and defend coding agents.

6 snips
Jul 20, 2026 • 41min
Legal Developments Every CISO Needs to Know | Larry Dietz - #293
Larry Dietz, attorney and cybersecurity expert and former Symantec exec, breaks down three major legal shifts affecting security leaders. They cover the lapse of a surveillance authority, the Supreme Court’s geofence ruling and its privacy implications, and the DoD’s pause on CMMC Level 2. Short, practical conversations on data access, retention, compliance, and legal risk management.


