

CISO Tradecraft®
G Mark Hardy & Ross Young
You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level.
© Copyright 2025, National Security Corporation. All Rights Reserved
© Copyright 2025, National Security Corporation. All Rights Reserved
Episodes
Mentioned books

Oct 6, 2025 • 27min
#253 - DARPA’s AI Cyber Challenge Unveiled (with Andrew Carney)
Dive into an exciting discussion on CISO Tradecraft as host G Mark Hardy engages with DARPA's AI Cyber Challenge director, Andrew Carney. Learn about the world of autonomous systems capable of identifying and fixing vulnerabilities at an unprecedented speed and scale. Discover the highs and lows of AIxCC's two-year journey, its groundbreaking impact on cybersecurity, and the potential it holds for the future. Whether you're a seasoned CISO or just passionate about cybersecurity, this episode is packed with insights on leveraging AI to protect critical infrastructure and defend against cyber threats. Don't miss it! https://aicyberchallenge.com/

16 snips
Sep 29, 2025 • 1h 6min
#252 - Master Storytelling for CISOs (with Neal Ford)
Neal Ford, a veteran in advertising and storytelling, shares his insights on impactful communication. He highlights the importance of emotional storytelling for cybersecurity leaders, explaining how it builds trust and connection. Ford discusses the balance of fear and hope in narratives and how personalizing threats motivates action. He emphasizes that effective storytelling can amplify influence and relevance in one's career. With practical tips on branding and continuous improvement, Ford inspires listeners to embrace their stories to engage others.

Sep 22, 2025 • 44min
#251 - AI Just Changed Data Security Requirements with Ronan Murphy
Learn how to elevate Data Protection in the Age of AI with Ronan Murphy In this episode of CISO Tradecraft, host G Mark Hardy and guest Ronan Murphy, Chief Strategy Officer at Forcepoint, discuss the critical importance of data protection for enterprises in the age of AI. Discover expert insights on common mistakes CISOs make, how AI revolutionizes data security, and the evolving role of CISOs from enforcers to strategists. Learn about effective data governance, AI’s impact on data, and leveraging tools like DLP & CASB for robust cybersecurity.
Plus, hear about Forcepoint Aware 2025 and actionable strategies for elevating your organization's data security posture. https://www.forcepoint.com/aware
Chapters
00:00 Introduction: The Importance of Data Security
00:26 Meet the Expert: Ronan Murphy's Background
02:40 Challenges in Data Protection
04:01 The Role of AI in Data Security
06:26 Strategies for Effective Data Management
19:05 Understanding Data Loss Prevention (DLP)
20:36 Exploring Cloud Access Security Brokers (CASB)
24:37 Data Security Posture Management (DSPM)
38:36 The Future Role of CISOs
40:30 Conclusion and Upcoming Events

Sep 15, 2025 • 47min
#250 - Understanding Vulnerabilities, Exploits, and Cybersecurity
Join host G Mark Hardy on CISO Tradecraft as he welcomes Patrick Garrity from VulnCheck and Tod Beardsley from Run Zero to discuss the latest in cybersecurity vulnerabilities, exploits, and defense strategies. Learn about their backgrounds, the complexities of security research, and strategies for effective communication within enterprises. The discussion delves into vulnerabilities, the significant risks posed by ransomware, and actionable steps for CISOs and security executives to protect their organizations. Stay tuned for invaluable insights on cybersecurity leadership and management.
Chapters
00:00 Introduction and Guest Welcome
00:57 Meet Patrick Garrity: Security Researcher and Skateboard Enthusiast
02:12 Meet Todd Beardsley: From Hacker to Security Research VP
03:58 The Evolution of Vulnerabilities and Patching
07:06 Understanding CVE Numbering and Exploitation
14:01 The Role of Attribution in Cybersecurity
16:48 Cyber Warfare and Global Threat Landscape
20:18 The Rise of International Hacking
22:01 Delegation of Duties in Offensive Warfare
22:25 The Role of Companies in Cyber Defense
23:00 Attack Vectors and Exploits
24:25 Real-World Scenarios and Threats
28:46 The Importance of Communication Skills for CISOs
31:42 Ransomware: A Divisive Topic
38:39 Actionable Steps for Security Executives
45:58 Conclusion and Final Thoughts

Sep 8, 2025 • 43min
#249 - Unveiling AI and Crypto Threats with Microsoft's Tomas Roccia
In this episode of CISO Tradecraft, host G Mark Hardy sits down with Tomas Roccia, a senior threat researcher at Microsoft, to delve into the evolving landscape of AI and cybersecurity. From AI-enhanced threat detection to the complexities of tracking cryptocurrency used in cybercrime, Tomas shares his extensive experience and insights. Discover how AI is transforming both defensive and offensive strategies in cybersecurity, learn about innovative tools like Nova for adversarial prompt detection, and explore the sophisticated techniques used by cybercriminals in high-profile crypto heists. This episode is packed with valuable information for cybersecurity professionals looking to stay ahead in a rapidly changing field.
Defcon presentation: Where is my crypto Dude? https://media.defcon.org/DEF%20CON%2033/DEF%20CON%2033%20presentations/Thomas%20Roccia%20-%20Where%E2%80%99s%20My%20Crypto%2C%20Dude%20The%20Ultimate%20Guide%20to%20Crypto%20Money%20Laundering%20%28and%20How%20to%20Track%20It%29.pdf
GenAI Breaches Generative AI Breaches: Threats, Investigations, and Response - Speaker Deck https://speakerdeck.com/fr0gger/generative-ai-breaches-threats-investigations-and-response
Transcripts: https://docs.google.com/document/d/1ZPkJ9P7Cm7D_JdgfgNGMH8O_2oPAbnlc
Chapters
00:00 Introduction to AI and Cryptocurrencies
00:27 Welcome to CISO Tradecraft
00:55 Guest Introduction: Tomas Roccia
01:06 Tomas Roccia's Background and Career
02:51 AI in Cybersecurity: Defensive Approaches
03:19 The Democratization of AI: Risks and Opportunities
06:09 AI Tools for Cyber Defense
08:09 Challenges and Limitations of AI in Cybersecurity
09:20 Microsoft's AI Tools for Defenders
12:13 Open Source AI Security: Project Nova
18:37 Community Contributions and Open Source Projects
19:30 Case Study: Babit Crypto Hack
22:12 Money Laundering Techniques in Cryptocurrency
23:01 AI in Tracking Cryptocurrency Transactions
26:09 Sophisticated Attacks and Money Laundering
33:50 Future of AI and Cryptocurrency
38:17 Final Thoughts and Advice for Security Executives
41:28 Conclusion and Farewell

Sep 1, 2025 • 12min
#248 - A Black Hat Chat with ThreatLocker CEO Danny Jenkins
In this episode of CISO Tradecraft, host G Mark Hardy sits down with Danny Jenkins, CEO and founder of ThreatLocker, live from the Black Hat conference. Danny shares insights into his technical background and explains how a customer-focused culture drives innovation and improvement at ThreatLocker. Learn about the company's unique practices, such as their 'control alt delight' sessions, 24/7 customer support, and how leadership at ThreatLocker leads by example. Danny also discusses the importance of learning from failures and removing obstacles for team members to help the company and its products continually evolve.
Danny's LinkedIn - https://www.linkedin.com/in/dannyjenkinscyber/
ThreatLocker - https://www.threatlocker.com/
Transcripts -https://docs.google.com/document/d/1TOib3nTXwrWuwF6sJMlVjTFurgr-jc1b
Chapters
00:00 Introduction and Welcome
00:27 Meet Danny Jenkins, CEO of Threat Locker
01:12 The Philosophy Behind Threat Locker
02:52 Customer-Centric Culture at Threat Locker
04:32 Technical Leadership and Personal Insights
08:55 Leadership Advice for Aspiring CISOs
11:22 Conclusion and Farewell

Aug 25, 2025 • 35min
#247 - What most leaders don't understand about AI (with Dave Lewis)
In this episode of CISO Tradecraft, host G Mark Hardy engages in an insightful conversation with Dave Lewis, Global Advisory CISO from 1Password, about AI governance and its importance in cybersecurity. They discuss AI policy and its implications, the evolving nature of AI and cybersecurity, and the critical need for governance frameworks to manage AI safely and securely. The discussion delves into the visibility challenges, shadow AI, the role of credentials, and the importance of maintaining fundamental security practices amidst rapid technological advancements. They also touch on the potential risks associated with AI, the misconceptions about its impact on jobs, and the need for a balanced approach to leveraging AI in a beneficial manner while safeguarding against its threats. This episode provides valuable guidance for cybersecurity professionals and organizations navigating the complexities of AI governance.
Chapters
00:00 Introduction to AI Governance
00:30 Guest Introduction: Dave Lewis
00:49 The Importance of AI Governance
01:42 Challenges in AI Implementation
03:20 AI in the Modern Enterprise
03:49 Shadow AI and Security Concerns
04:49 AI's Impact on Jobs and Industry
05:27 The Gartner Hype Cycle and AI
05:43 AI's Influence on the Stock Market
06:14 Historical Context of AI
06:32 AI and Credential Security
08:29 The Role of Governance in AI
12:47 The Future of AI and Security
18:36 Governance and Policy Recommendations
19:26 AI Governance and Ethical Concerns
20:01 AI Self-Preservation and Human Safety
20:18 Uncontrollable AI Applications
21:17 Vectors of AI Trouble
21:58 AI Hallucinations and Data Security
22:53 AI Vulnerabilities and Exploits
26:29 Deepfakes and AI Misuse
27:33 Historical Cybersecurity Incidents
29:04 Future of AI and Job Security
33:47 Managing AI Identities and Credentials
34:21 Conclusion and Final Thoughts

Aug 18, 2025 • 44min
#246 - Tim Brown on SolarWinds: What Every CISO Should Know
In this episode of the CISO Tradecraft podcast, host G Mark Hardy speaks with Tim Brown, the CISO of SolarWinds, at the Black Hat conference in Las Vegas. They delve into the details of the infamous SolarWinds breach, discussing the timeline of events, the involvement of the Russian SVR, and the immediate and long-term responses by SolarWinds. Tim shares insights on the complexities of supply chain security, the importance of clear communication within an organization, and the evolving regulatory landscape for CISOs. Additionally, they discuss the personal and professional ramifications of dealing with such a high-profile incident, offering valuable lessons for current and future cybersecurity leaders.
Chapters
00:00 Introduction and Welcome
00:59 The SolarWinds Incident Unfolds
03:13 Understanding the Attack and Response
04:04 The Role of SVR and Supply Chain Security
10:43 Technical Details of the Attack
14:56 Compliance and Reporting Challenges
19:24 Rebuilding Trust and Personal Impact
22:06 CISO Concerns and Company Support
22:14 Legal Challenges and Company Expenses
23:40 SEC Charges and Legal Proceedings
29:35 Supply Chain Security and Vendor Assurance
35:47 CISO Accountability and Industry Standards
39:41 Final Thoughts and Advice for CISOs

Aug 11, 2025 • 46min
#245 - Mastering Cybersecurity Recruitment and Career Growth (with Casey Marquette)
In this episode of CISO Tradecraft, host G Mark Hardy is joined by cybersecurity expert Casey Marquette to discuss effective HR and recruiting strategies for building a top-notch cybersecurity team. They dive into career development, the importance of networking, and how to navigate the challenges of hiring in cybersecurity. Casey shares his personal journey from law enforcement to becoming a leading figure in the cybersecurity world, highlighting the role of mentorship and continuous learning. The episode also covers innovative uses of AI in the hiring process and provides practical advice for both hiring managers and job seekers in the cybersecurity field. Tune in for valuable insights on how to hire the best talent and advance your career in cybersecurity.
Transcripts https://docs.google.com/document/d/1c-3qy6KkQuhjuHquycQ3rRwMdSlZBfz4
Chapters
00:00 Introduction to Cybersecurity Recruitment
00:31 Guest Introduction: Casey Marquette
01:46 Casey's Career Journey
04:41 Hiring for Attitude vs. Skillset
05:30 Promoting from Within vs. Hiring Externally
07:34 Leadership and Morale
20:20 The Importance of Networking and Mentorship
22:19 AI in Recruitment
23:30 The Talent Pool and Recruitment Challenges
24:04 Introducing Scout: The AI Recruitment Tool
24:51 Security Measures in AI Recruitment
25:32 Addressing Fraudulent Candidates
26:10 Remote Hiring and Deepfake Concerns
28:52 Insider Threats and Tabletop Exercises
31:51 Enhancing Career Marketability for CISOs
37:47 Building Effective Networks and Relationships
42:04 The Importance of Specialized Recruitment
44:21 Final Thoughts and Contact Information

Aug 4, 2025 • 45min
#244 - Breaking into Cybersecurity (with Christophe Foulon)
Join host G Mark Hardy in another enlightening episode of CISO Tradecraft as he speaks with special guest Christophe Foulon, a seasoned cybersecurity professional and podcast host. In this episode, Christophe delves into his journey from the help desk to cybersecurity expert, the challenges faced by newcomers, and the keys to successfully building and leading cybersecurity teams. Learn about the importance of continuous learning, managing career transitions, and the emotional rewards and challenges of being a CISO. Whether you're an aspiring CISO or looking to advance in your cybersecurity career, this episode offers invaluable insights and practical advice.
Christophe's LinkedIn: https://www.linkedin.com/in/christophefoulon/ Christophe's Website: https://christophefoulon.com/
Christophe's Podcast: https://podcasts.apple.com/us/podcast/breaking-into-cybersecurity/id1463136698
Transcripts: https://docs.google.com/document/d/1UytoyelIMezzbtxdPHo5FE_oLiXYS_58
Chapters
00:00 Introduction to the Episode
00:27 Meet the Guest: Christophe Foulon
01:30 Christophe's Journey into Cybersecurity
06:24 The Allure and Challenges of a CISO Role
09:55 Developing Political and Leadership Skills
20:30 Aligning Team Members with Their Strengths
31:34 Navigating HR and Diversity in Cybersecurity
36:29 Becoming a Fractional or Virtual CISO
42:27 Final Thoughts and How to Connect with Christophe