

CISO Tradecraft®
G Mark Hardy & Ross Young
You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level. © Copyright 2025, National Security Corporation. All Rights Reserved
Episodes
Mentioned books

Jul 29, 2025 • 27min
#243 - Navigating Hacker Summer Camp in 2025
Navigating Hacker Summer Camp: A Comprehensive Guide Join host G Mark Hardy on this episode of CSO Tradecraft as he provides a detailed guide on what to expect at Hacker Summer Camp, a series of significant cybersecurity events including DEFCON, Black Hat, and BSides Las Vegas. G Mark shares historical insights, tips for first-timers, and personal anecdotes from his extensive experience attending these events over the years. Learn about the origins, key activities, and networking opportunities that make these conferences pivotal in the cybersecurity community. Stay tuned for practical advice on planning your visit and making the most out of your Hacker Summer Camp experience.
Transcripts: https://docs.google.com/document/d/1Y-MenErnVCzUga4xu20ZIz8hT9xsGSJD
Chapters
00:00 Introduction to Hacker Summer Camp
01:29 History and Significance of DEFCON
02:50 Spot the Fed and Early DEFCON Experiences
05:31 The Evolution of Black Hat
09:34 The Birth and Growth of BSides
11:19 Tips for Attending Hacker Summer Camp
19:57 Networking and Participation Strategies
25:31 Conclusion and Final Thoughts

16 snips
Jul 21, 2025 • 46min
#242 - The Secret to Career Success: Your Personal Board of Directors
In this enlightening conversation, cybersecurity expert Ross Young shares insights on creating a personal board of directors for career advancement. He emphasizes the value of mentorship and sponsorship, explaining how informal relationships can outperform formal coaching. Discover the importance of diversifying board members, including ‘grave diggers’ to identify organizational issues. Ross offers practical tips for effectively approaching and maintaining connections with mentors, ultimately guiding listeners on how to strategically navigate their career paths.

Jul 14, 2025 • 26min
#241 - The OWASP Threat and Safeguard Matrix (with Ross Young)
Join G Mark Hardy in this special episode of CISO Tradecraft as he interviews Ross Young, the creator of the OWASP Threat and Safeguard Matrix (TaSM). Ross shares his extensive cybersecurity background and discusses the development and utility of the TaSM, including its applications in threat modeling and risk management. Additionally, Ross introduces his upcoming book, 'Cybersecurity's Dirty Secret: How Most Budgets Are Wasted,' and provides insights on maximizing cybersecurity budgets. Don't miss this episode for essential knowledge on enhancing your cybersecurity leadership and strategies.
OWASP Threat and Safeguard Matrix - https://owasp.org/www-project-threat-and-safeguard-matrix/
Transcripts - https://docs.google.com/document/d/1anGewI3XccGnXoV3oE2h7BfelY5QxiSL/
Chapters
00:00 Introduction to the Threat and Safeguard Matrix
00:30 Meet Ross Young: Cybersecurity Expert
01:08 Ross Young's Career Journey
01:59 The Upcoming Book: Cybersecurity's Dirty Secret
03:04 Introduction to the Threat and Safeguard Matrix (TaSM)
03:48 Understanding the TaSM Framework
07:10 Applying the TaSM to Real-World Scenarios
19:32 Using TaSM for Threat Modeling and Risk Committees
21:58 Extending TaSM Beyond Cybersecurity
23:52 AI Risks and the TaSM
24:43 Conclusion and Final Thoughts

Jul 7, 2025 • 48min
#240 - From CruiseCon to AI Threats (with Ira Winkler)
Join us for an engaging episode of CISO Tradecraft, hosted by G Mark Hardy, featuring cybersecurity veteran Ira Winkler. In this episode, we dive deep into cybersecurity careers, discuss the unique CruiseCon cybersecurity event, and explore the evolution of information security. Hear firsthand accounts of career journey highlights, networking strategies, and the importance of democratizing top-tier content. Learn about the impacts of AI in cybersecurity, data poisoning, and upcoming cybersecurity conferences. Whether you're a seasoned professional or just starting your journey, this episode is packed with invaluable insights and advice.
https://cruisecon.com/
Don't forget to the the following code for 10% off "CISOTRADECRAFT10"
Transcripts: https://docs.google.com/document/d/1-H1CShsyirr4ZL9d1WCx6IMA_ngjWoEN
Chapters
00:00 Introduction to CISO Tradecraft
01:34 Meet Ira Winkler: Cybersecurity Veteran
02:50 The Concept of CruiseCon
05:58 Challenges in Cybersecurity Events
08:03 Building a Cybersecurity Community
13:45 Mentorship and Networking in Cybersecurity
21:52 The Importance of Relevant Mentorship
24:40 The Importance of Programmatic Principles
25:19 Finding the Right Mentor for Your Career Path
26:38 Adapting to a Shifting Career Landscape
27:05 Understanding AI Fundamentals
29:12 The Role of Data in AI
30:57 Agentic AI and Its Applications
32:48 Challenges and Risks in AI
41:33 Upcoming Events and Keynote Speakers
43:35 Leadership Lessons from Ground Zero
46:39 Future Cruise Con Events
47:44 Conclusion and Farewell

9 snips
Jun 30, 2025 • 45min
#239 - Actionable Gamification and Lasting Success (with Yu-Kai Chou)
Yu-Kai Chou, a gamification pioneer and author, shares insights on how to harness play for success in life and career. He explains his Octalysis framework, emphasizing the importance of aligning passions with skills and selecting meaningful life games. The conversation delves into practical advice for knowing personal attributes, enhancing skills, and building alliances. Chou argues that reframing dedicated practice as enjoyable play can unlock legendary success, encouraging listeners to find their true passions and embark on quests for continuous growth.

Jun 23, 2025 • 45min
#238 - The Impact of the Israel Iran Conflict (with Nathan Case)
In this episode of CISO Tradecraft, host G Mark Hardy discusses the ongoing Israel-Iran conflict and its potential cyber implications with cybersecurity expert Nathan Case. They delve into lessons learned from the Russia-Ukraine conflict, discuss the effectiveness of cyber warfare, and evaluate Iran's cyber capabilities. The conversation also covers the ethical implications of cyber attacks, dual-use targets, and the danger of supply chain vulnerabilities. Practical advice is provided on improving cybersecurity measures, including the importance of MFA, network segmentation, and evaluating internal threats. Join us for an in-depth look at how current geopolitical tensions can impact global cybersecurity.
Nathan Case - https://www.linkedin.com/in/nathancase/
Chapters
00:00 Introduction to the Israel-Iran Conflict
00:52 Meet the Expert: Nate Case
01:51 Cyber Warfare Insights from Russia-Ukraine Conflict
03:36 The Impact of Cyber on Critical Infrastructure
08:00 Ethics and Rules of Cyber Warfare
15:01 Iran's Cyber Capabilities and Strategies
16:56 Historical Context and Modern Cyber Threats
23:28 Foreign Cyber Threats: The Iranian Example
24:06 Israel's Cyber Capabilities
25:39 The Role of Cyber Command
26:23 Challenges in Cyber Defense
27:11 The Complexity of Cyber Warfare
32:21 Ransomware and Attribution Issues
36:13 Defensive Cyber Operations
39:39 Final Thoughts and Recommendations

Jun 16, 2025 • 42min
#237 - Build a World Class SOC (with Carson Zimmerman)
Join G Mark Hardy and Carson Zimmerman, the author of '11 Strategies of a World-Class Cybersecurity Operations Center,' in this insightful episode of CISO Tradecraft. Carson shares his career journey, the evolution from the 10 to 11 strategies, and delves into the future needs of Security Operations Centers (SOCs). They discuss critical topics such as the importance of continuous improvement, AI's impact on SOCs, and the value of embracing neurodiversity in cybersecurity teams. Whether you're a seasoned cybersecurity leader or an aspiring professional, get actionable advice on how to enhance and revolutionize your SOC operations.
11 Strategies of a World Class Cybersecurity Operations Center https://www.mitre.org/sites/default/files/2022-04/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf
14 Questions are all you need - https://www.first.org/resources/papers/conf2024/1445-14-Questions-Carson-Zimmerman.pdf
Transcripts - https://docs.google.com/document/d/1WVJi9WkxOG7yedQYWSooiqRFjBERd9kV
Chapters
00:00 Introduction and Guest Welcome
00:53 Background and Book Discussion
03:33 SOC Challenges and Stagnation
06:10 Managing SOC Alerts and Burnout
09:26 SOC Evolution and Neurodiversity
23:50 Career Progression in Cybersecurity
30:28 Impact of AI on SOC Operations
40:07 Final Thoughts and Conclusion

Jun 9, 2025 • 47min
#236 - Build a World Class GRC Program (with Matt Hillary)
Matt Hillary, Chief Information Security Officer at Drata, shares his expertise in governance, risk, and compliance. He discusses the evolution of GRC from spreadsheets to automated platforms, emphasizing compliance as code. Matt highlights leveraging AI for faster responses in compliance processes and the importance of effective risk management. He also touches on common pitfalls in GRC programs and the significance of mental health for cybersecurity leaders, underscoring the challenges and opportunities in today’s compliance landscape.

Jun 2, 2025 • 41min
#235 - Grey is the New Black (with Ryan Gooler)
Join G Mark Hardy at THOTCON in Chicago for an insightful podcast episode on building a successful cybersecurity career. Featuring guest Ryan Gooler, they discuss the non-linear paths to success, the value of mentorship, financial planning, and the importance of continuous learning and adapting. Learn how to navigate career transitions, embrace risks, and find joy in teaching and learning from others in the cybersecurity community.
Transcripts: https://docs.google.com/document/d/1nsd61mkIWbmIL1qube0-cdqINsDujAVH
Chapters
00:00 Welcome to THOTCON: Meeting Amazing People
00:26 Introducing Ryan Gooler: A Journey into Cybersecurity
04:09 The Value of Mentorship in Cybersecurity
06:22 Career Management and Setting Goals
09:33 Financial Planning for Cybersecurity Professionals
16:40 Automating Finances and Smart Spending
21:25 Financial Sophistication and Mutual Funds
22:07 Automating Life Tasks
22:41 The Concept of a Finishing Stamp
24:17 Leadership and Delegation in the Navy
26:06 Building and Maintaining Culture
27:21 Surviving Toxic Environments
29:55 Taking Risks and Finding Joy
34:34 Advice for Cybersecurity Careers
39:01 The Importance of Teaching and Learning
40:29 Conclusion and Farewell

May 26, 2025 • 33min
#234 - Model Context Protocol (MCP)
In this episode of CISO Tradecraft, host G Mark Hardy delves into the emerging concept of Model Context Protocol (MCP) and its significance in AI and enterprise security. Launched by Anthropic in November 2024, MCP is designed to standardize how AI systems interact with external data sources and applications. Hardy explores how MCP differs from traditional APIs, its implications for security, and the steps organizations need to take to prepare for its adoption. Key topics include the stateful nature of MCP, security risks such as prompt injection and tool poisoning, and the importance of developing a robust governance framework. By the end of the episode, listeners will have a comprehensive understanding of MCP and practical recommendations for safeguarding their AI-driven workflows.
Transcripts https://docs.google.com/document/d/1vyfFJgTbsH73CcQhtBBkOfDoTrJYqzl_
References
Model Context Protocol specification and security best practices, https://modelcontextprotocol.io
Security risks of MCP, https://pillar.security
MCP security considerations, https://writer.com
Chapters
00:00 Introduction to Model Context Protocol (MCP)
00:27 Understanding MCP and Its Importance
01:41 How MCP Works and Its Security Implications
04:23 Comparing MCP to Traditional APIs
08:41 MCP Architecture and Security Benefits
12:07 Top Security Risks of MCP
18:00 Implementing Security Controls for MCP
25:00 Governance Framework for MCP
28:03 Future Trends and Strategic Recommendations
30:34 Conclusion and Next Steps


