
CISO Tradecraft®
Welcome to CISO Tradecraft®, your guide to mastering the art of being a top-tier Chief Information Security Officer (CISO). Our podcast empowers you to elevate your information security skills to an executive level. Join us on this journey through the domains of effective CISO leadership.
© Copyright 2025, National Security Corporation. All Rights Reserved
Latest episodes

Dec 2, 2024 • 49min
#209 - AI Singularity (with Richard Thieme)
In this riveting episode of CISO Tradecraft, host G Mark Hardy welcomes back Richard Thieme, a thought leader in cybersecurity and technology, almost three years after his last appearance. Richard delves into the necessity of thinking like a hacker, provides insights into the AI singularity, and discusses the ethical and societal implications of emerging technologies. The conversation also touches on Richard's extensive body of work, including his books and views on cyber warfare, disinformation, and ethical decision-making. Tune in for a thought-provoking discussion that challenges conventional wisdom and explores the interconnectedness of technology, consciousness, and our future.
Big Thanks to our Sponsor CruiseCon - https://cruisecon.com/
CruiseCon Discount Code: CISOTRADECRAFT10
Link to Richard’s home page (and links to Amazon for his books):
https://thiemeworks.com/
Link to the book, The Ending of Time:
https://store.kfa.org/products/the-ending-of-time-new-edition
Transcripts: https://docs.google.com/document/d/1Q7CJkF7Spji2iAbV_mYEyYHnKWobzo6N
Chapters
00:00 Introduction and Guest Announcement
00:56 Upcoming Cybersecurity Event: CruiseCon
01:41 Welcoming Back Richard Thieme
02:06 Reflecting on Past Discussions
02:59 The Necessity for Thinking Like a Hacker
03:10 Exploring Richard Thieme's Books
08:25 Understanding AI and Its Implications
18:28 Soft Power and Global Influence
24:01 The Power of Fiction in Revealing Truth
24:37 Ethical Frameworks Post 9/11
26:12 The Role of Empathy in Intelligence Work
26:37 The Blurring Line Between Fact and Fiction
29:52 The Isolation of Intelligence Work
31:18 The Interconnectedness of Everything
33:36 Exploring Remote Viewing and Consciousness
36:50 The Rise of AI and Ethical Considerations
39:43 The Evolution of Technology and Society
45:07 Final Thoughts and Reflections

22 snips
Nov 25, 2024 • 45min
#208 - Insider Threat (with Shawnee Delaney)
Shawnee Delaney, an insider threat expert with a background in espionage, shares her insights into cybersecurity's human elements. She highlights how understanding motivation is vital for detecting insider threats and stresses the importance of cultivating a positive organizational culture. Delaney discusses proactive strategies like psychological testing in hiring and employee lifecycle management. She also offers practical advice for leaders to foster open communication and build effective insider threat programs, drawing parallels from military core values.

Nov 18, 2024 • 46min
#207 - CISO Burnout (with Raghav Singh)
Welcome to another enlightening episode of CISO Tradecraft! In this episode, host G. Mark Hardy dives deep into the critical topic of CISO burnout with special guest Raghav Singh, a PhD candidate from the University of Buffalo. This is an eye-opening session for anyone in the cybersecurity field, especially those in or aspiring to the CISO role. Raghav shares valuable insights from his extensive research on the unique stresses faced by CISOs, the organizational factors contributing to burnout, and practical coping mechanisms. We also explore the evolutionary phases of CISOs, from technical experts to strategic business enablers. Whether you're dealing with resource limitations, seeking executive support, or managing ever-evolving cybersecurity threats, this episode offers actionable advice to navigate the demanding role of a CISO successfully. Don't forget to like, comment, and share to help other CISOs and cybersecurity leaders!
Big Thanks to our Sponsor CruiseCon - https://cruisecon.com/
CruiseCon Discount Code: CISOTRADECRAFT10
Transcripts: https://docs.google.com/document/d/1fhLkaj_JetlYFQ50Q69uMGmsw3fS3Wqa
CISO Burnout - https://aisel.aisnet.org/amcis2023/sig_lead/sig_lead/4/
CISO-CIO Power Dynamics https://aisel.aisnet.org/amcis2024/is_leader/is_leader/6/
Cybersec professionals and AI integration https://aisel.aisnet.org/amcis2024/security/security/29/
Raghav can be reached on rsingh45@buffalo.edu
Chapters
00:00 Introduction and Guest Welcome
02:34 Understanding CISO Burnout
03:24 PhD Journey and Challenges
10:12 Key Findings on CISO Burnout
18:39 Six Sources of CISO Burnout
32:47 CISO Maturity Levels
42:57 Conclusion and Call to Action

Nov 11, 2024 • 46min
#206 - Ira Winkler CruiseCon Founder
Setting Sail with Cybersecurity: Exclusive Insights from Ira Winkler on CruiseCon 2025 🛳️ Join us for an exciting episode of CISO Tradecraft as G Mark Hardy sits down with renowned cybersecurity expert Ira Winkler! Discover the groundbreaking CruiseCon 2025, the first at-sea cybersecurity conference, featuring top-tier speakers and unrivaled networking opportunities. Learn about Ira's illustrious career, the significance of certifications, and the current state of the cybersecurity job market. Don't miss out on this chance to enhance your career and connect with industry luminaries.
Big Thanks to our Sponsor CruiseCon - https://cruisecon.com/
CruiseCon Discount Code: CISOTRADECRAFT10
Transcripts: https://docs.google.com/document/d/1CGyFBxOrxvJitKsH9BRKwf2_g8rRPZ6K
Chapters
00:00 Introduction and Special Announcement
00:42 Reconnecting with Ira Winkler
04:07 Early Cybersecurity Days and Certifications
14:35 Innovative Ideas and CruiseCon
21:32 Meet the Top Cybersecurity Experts
22:13 Exciting Events and Networking Opportunities
24:10 Special Deals and Sponsorships
34:47 Addressing the Cybersecurity Job Market

Nov 4, 2024 • 46min
#205 - Wisdom from the 1st Cyber Colonel (JC Vega)
Join G. Mark Hardy on this exciting episode of CISO Tradecraft as he interviews J.C. Vega, the first cyber colonel in the United States Army. Vega shares his invaluable insights on leadership, team building, and success strategies that can transform your cybersecurity career. Plus, learn about CruiseCon 2025, Wee Dram, and how you can take your leadership skills to the next level. Don't miss out on this episode packed with wisdom, actionable advice, and some fun anecdotes. Subscribe, comment, and share with your peers!
Big Thanks to our Sponsor CruiseCon - https://cruisecon.com/
CruiseCon Discount Code: CISOTRADECRAFT10
JC Vega - https://www.linkedin.com/in/jcvega-cyber-colonel/
Transcripts: https://docs.google.com/document/d/1ExuX-WVO4_qqLoIZDuT0QS2VAvN2resW
Chapters
00:00 Introduction and Special Guest Announcement
01:15 Meet J.C. Vega: The First Cyber Colonel
01:55 The Wee Dram Community
03:39 Building a Trusted Cybersecurity Community
09:12 Leadership Principles from Military to Civilian Life
12:31 Building and Leading Effective Teams
24:17 The Peter Principle and Career Progression
24:49 Creating a Shared Understanding in Cybersecurity
26:43 Commander's Intent: Defining Success
29:29 Empowering Teams and Accepting Prudent Risk
36:19 Rules to Live By: The Vega's Top Three
44:58 Final Thoughts and Farewell

Oct 28, 2024 • 24min
#204 - Shadows and Zombies in the Data Center
This spooky installment explores the lurking threats of Shadow IT and Zombie IT. Discover the risks associated with unauthorized technologies and obsolete systems that can compromise organizational security. Strategies like rigorous asset management and automation are highlighted to combat these hidden dangers. The discussion also emphasizes the need for comprehensive compliance reviews. Plus, there’s an enticing opportunity to network at an upcoming cybersecurity conference aboard a luxury cruise.

Oct 21, 2024 • 17min
#203 - Be SOCcessful with the SOC-CMM
Unlocking SOC Excellence: Master the SOC Capability Maturity Model Join host G Mark Hardy in this compelling episode of CISO Tradecraft as he explores the revolutionary SOC Capability Maturity Model (SOC CMM) authored by Rob van Os. This episode is a must-watch for CISOs, aspiring CISOs, and cybersecurity professionals aiming to optimize their Security Operations Center (SOC). Learn how to measure, evaluate, and enhance your SOC's maturity across key domains including Business, People, Process, Technology, and Services. Gain insights into leveraging radar charts for visualizing SOC capabilities and hear case studies such as a mid-sized financial company’s remarkable improvements. Discover why understanding your SOC's strengths and weaknesses and conducting risk-based improvement planning are crucial. Don't miss out—elevate your cyber resilience today, subscribe, and share with your network to set your SOC on the path to excellence!
References:
SOC-CMM - https://www.soc-cmm.com/products/soc-cmm/
Robert van Os - https://www.linkedin.com/in/socadvisor/
Transcripts: https://docs.google.com/document/d/1Fk6_t9FMyYXDF-7EfgpX_ZjLc0iPAgfN
Chapters
00:12 Introduction to CISO Tradecraft and SOCs
01:20 Understanding SOC CMM: A Game-Changing Tool
02:29 Evaluating SOC Maturity and Capability
06:04 Benefits and Implementation of SOC CMM
07:56 Understanding SOC Assessments
08:55 Deep Dive into SOC CMM Domains
12:42 Benefits and Flexibility of SOC CMM
14:40 Real-World Application and Conclusion

Oct 14, 2024 • 45min
#202 - Cybersecurity Crisis: Are We Failing the Next Generation?
In this episode of CISO Tradecraft, host G Mark Hardy explores the challenges and misconceptions facing the next generation of cybersecurity professionals. The discussion covers the myth of a talent shortage, the shortcomings of current educational and certification programs, and the significance of aligning curricula with real-world needs. Hardy emphasizes the importance of hands-on experience, developing soft skills, and fostering continuous learning. The episode also highlights strategies for retaining talent, promoting internal training, and creating leadership opportunities to cultivate a skilled and satisfied cybersecurity workforce.
Transcripts: https://docs.google.com/document/d/12fI2efHXuHR4dS3cu7P0UIBCtjBdgREI
Chapters
00:00 Introduction to the Cybersecurity Talent Crisis
00:40 Debunking the Talent Shortage Myth
02:23 The Real Talent Gap: Mid-Career Professionals
03:04 Outsourcing and Its Impact on Entry-Level Jobs
08:29 Challenges in Cybersecurity Education
16:13 The Importance of Practical Skills Over Theory
23:52 The Importance of Writing Skills
25:10 Continuous Learning and Self-Investment
26:07 Performance and Career Progression
28:40 Mentorship and Onboarding
29:51 Training and Development Challenges
32:32 Retention Strategies
33:44 Engaging Junior Employees
39:07 Technology and Innovation
40:54 Conclusion and Final Thoughts

Oct 7, 2024 • 18min
#201 - Avoiding Hurricanes in the Cloud
In this episode of CISO Tradecraft, hosted by G Mark Hardy, you'll learn about four crucial tools in cloud security: CNAPP, CASB, CSPM, and CWPP. These tools serve various functions like protecting cloud-native applications, managing access security, maintaining cloud posture, and securing cloud workloads. The discussion covers their roles, benefits, key success metrics, and best practices for CISOs. As the cloud security landscape evolves, understanding and integrating these tools is vital for keeping your organization safe against cyber threats.
Transcripts: https://docs.google.com/document/d/1Mx9qr30RuWrDUw1TLNkUDQ8xo4xvQdP_
Chapters
00:00 Introduction to Cloud Security Tools
02:24 Understanding CNAPP: The Comprehensive Cyber Defense
08:13 Exploring CASB: The Cloud Access Gatekeeper
11:12 Diving into CSPM: Ensuring Cloud Compliance
13:40 CWPP: Protecting Cloud Workloads
15:08 Best Practices for Cloud Security
15:54 Conclusion and Final Thoughts

9 snips
Sep 30, 2024 • 45min
#200 - Copywriting AI (with Mark Rasch)
Mark Rasch, an attorney specializing in AI and cybersecurity, dives into the intricate legal landscape shaped by artificial intelligence. He discusses copyright challenges with AI-generated content and emphasizes the importance of training data. The conversation delves into ethical dilemmas, such as the decision-making in AI within critical fields like healthcare and self-driving cars. Rasch also highlights how biases in data can affect AI outcomes and the implications for information security policy. Tune in for a compelling exploration of AI's legalities and ethical considerations!
Remember Everything You Learn from Podcasts
Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.