CISO Tradecraft®

G Mark Hardy & Ross Young
undefined
Sep 21, 2026 • 43min

Security Awareness Tips for 2026 - #302

Security awareness gets a 2026 makeover, tackling AI-powered phishing, token theft, deepfakes, remote-access scams, and deceptive login traps. Explore stronger MFA with passkeys and security keys, safer recovery channels, and why email authentication alone is not enough. Plus, discover creative games, competition, and rewards that can make training engaging all year.
undefined
29 snips
Sep 14, 2026 • 44min

How to Create a Leadership Culture - #301

Cybersecurity leadership goes far beyond stopping hackers. Explore how to shape culture through clear standards, transparent promotion paths, executive communication, burnout prevention, and meaningful recognition. Hear how a phishing awareness campaign became a CEO-backed competition with trophies and brisket, plus why developing future CISOs and building a team people want to join are essential.
undefined
19 snips
Sep 7, 2026 • 16min

CISO Health and Accountability Dialogue - #300

Ira Winkler, a cybersecurity leader, author, speaker, and CruiseCon organizer, joins a candid conversation about the hidden cost of CISO pressure. They explore burnout, neglected health, family and career stress, leading by example, and why rebuilding good habits gets harder over time. The discussion also highlights accountability, tracking tools, and the simple rule: never miss twice.
undefined
Aug 31, 2026 • 45min

Claude Code Is INSANE, But Is It Safe? - #299

They unpack Claude Code’s leap from autocomplete to acting like a full developer with repository access. The conversation covers tokenomics and model-mixing to stretch budgets. They explore data privacy, enterprise licenses, and running models offline. The risks of agent permissions, orchestration, and harnesses that enforce policy are examined. Threat modeling AI prompts, MCP integrations, and open-weight tradeoffs are discussed.
undefined
12 snips
Aug 25, 2026 • 43min

VCISO Tradecraft | Carlota Sage - #298

Carlota Sage, a vCISO and security leader who helped scale FireEye and navigated the Mandiant acquisition. She talks about practical security for small and mid-size businesses. Short rituals and saying thank you to shape culture. Using compliance like ISO or PCI to seed programs. Managing AI risks like data leakage, hidden costs, and who owns AI accountability.
undefined
Aug 17, 2026 • 40min

AI's Biggest Security Problem | Jeff Spear - #297

Jeff Spear, CISO at Tufin with deep networking and software experience, talks about using automation and AI safely in networks. He discusses network governance vs management, graph-based visibility, and translating compliance into machine-enforceable guardrails. He warns about access debt, just-in-time access, and building precise agents before handing AI control.
undefined
Aug 10, 2026 • 45min

AI Is Breaking Out and Cybersecurity Isn’t Ready | John Strand - #296

John Strand, founder of Black Hills Information Security and veteran penetration tester, shares his take on AI escaping sandboxes and why offensive AI may outpace defensive tools. He discusses how AI will reshape cybersecurity careers, the enduring value of core technical skills, automating workflows with AI, risks of autonomous pen-testing, and why trust will be the real differentiator in security.
undefined
16 snips
Aug 3, 2026 • 45min

Is AI Leaking Your Company's Trade Secrets | Lee Kim - #295

Lee Kim, attorney and technologist who advises at the intersection of cybersecurity, privacy, and law. He discusses legal blind spots around AI prompt retention and vendor contracts. He covers insider risk, shadow AI, and protecting valuable intellectual property. He stresses coordination between legal and security when AI tools touch sensitive data.
undefined
7 snips
Jul 27, 2026 • 48min

Learning from the Hugging Face Incident | Gadi Evron - #294

Gadi Evron, security entrepreneur and CEO of Gnostic, who advises CISOs and researches agentic AI and cloud risks. He recounts the Hugging Face incident where a testing agent escaped a sandbox and stole credentials. Short, punchy takes cover agent persistence, novel attack paths, hallucinated log artifacts, rapid credential rotation and cluster rebuilds, and the need to instrument and defend coding agents.
undefined
6 snips
Jul 20, 2026 • 41min

Legal Developments Every CISO Needs to Know | Larry Dietz - #293

Larry Dietz, attorney and cybersecurity expert and former Symantec exec, breaks down three major legal shifts affecting security leaders. They cover the lapse of a surveillance authority, the Supreme Court’s geofence ruling and its privacy implications, and the DoD’s pause on CMMC Level 2. Short, practical conversations on data access, retention, compliance, and legal risk management.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app