

CISO Tradecraft®
G Mark Hardy & Ross Young
You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level. © Copyright 2025, National Security Corporation. All Rights Reserved
Episodes
Mentioned books

Nov 20, 2020 • 39min
#4 - Asset Management
If you want to assess your current level of security, then you should start with an asset management program. Asset management provides the basic building blocks to enable vulnerability management and remediation programs.
This podcast provides key lessons learned on what is required for effective asset management as well as discuss how asset management evolves with the cloud. Listeners will also learn important steps to take to create a world class asset management program.
Chapters
00:00 Introduction
02:00 The SANS Top 20 Controls
06:04 What if I don't have an Agent on my Endpoint?
09:08 Cloud Native CMDB Systems
11:35 Shadow IT in the Cloud
14:12 Software Bill of Materials for your Applications
19:33 What's the problem with older versions of software?
22:02 Is there a Vulnerability in Windows 10?
24:34 The Criticality of the Enterprise Patch Cycle
28:43 How do we have a Good Inventory?
31:34 Continuity of Operations & Disaster Recovery
33:17 Is your Asset Inventory Complete?
35:17 Is Asset Management Key for your Organization?

Nov 13, 2020 • 39min
#3 - How to Read Your Boss
The ability to persuade others is a core tradecraft for every CISO. This podcast discusses the most common styles of executive decision making (Charismatics, Thinkers, Skeptics, Followers, and Controllers). After listening to this podcast, you will understand how to more effectively tailor your message to best influence each style of executive.
If you would like to learn more about this topic, we strongly recommend you read the Harvard Business Review article, “Change the Way You Persuade”, by Gary A. Williams and Robert B. Miller
https://hbr.org/2002/05/change-the-way-you-persuade
Chapters
00:00 Introductions
03:04 How to Persuade a Charismatic Leader
06:49 How do you use Visual Aids to Help Thinkers
10:39 What approaches do you take with Skeptics?
15:47 How do we overcome Skeptics?
17:24 Are Followers Leaders?
20:58 Can we do a Pilot Program?
22:59 Strategic Tools to be more Successful in your Career
24:47 Do you have any experiences with Controllers?
28:03 How to use your Egos and their Past Experiences to your Advantage
31:06 The Pointy Haired Boss
36:35 How to Adapt a Leader's Style

Nov 6, 2020 • 46min
#2 - Principles of Persuasion
To become an effective CISO you need influence skills. On this episode we explore Robert Cialdini's book, "Influence" and discuss the psychology of persuasion. We will explore 6 key areas of influence:
Liking- If people like you - because they sense that you like them, or because of things you have in common - they're more apt to say yes to you
Reciprocity- People tend to return favors. If you help people, they'll help you. If you behave in a certain way (cooperatively, for example), they'll respond in kind
Social Proof- People will do things that they see other people doing- especially if those people seem similar to them
Commitment and Consistency- People want to be consistent, or at least to appear to be. If they make a public, voluntary commitment, they'll try to follow through
Authority- People defer to experts and to those in positions of authority (and typically underestimate their tendency to do so)
Scarcity- People value things more if they perceive them to be scarce
If you would like to more on this topic, then we recommend you read Cialdini's work:
Website https://www.influenceatwork.com/principles-of-persuasion/
Book https://www.amazon.com/Influence-Psychology-Persuasion-Robert-Cialdini/dp/006124189X
Chapters
00:00 Introduction
03:21 The Principles of Persuasion
05:27 How to be a Great Speaker and Get People to Like You
09:01 How to Win Friends and Influence People
13:45 How does a Mint Influence your Tipping?
15:04 Doing a Favor for Someone is a Good Thing
17:29 The Concept of Social Proof is Security
21:34 How to Defend against Audits
26:15 Getting Small Commitments Out of People Early On
29:20 The Importance of Consistency in Influencing
34:12 The Six Principles of Persuasion
38:57 Is there a Scarcity of Time?
43:13 The Six Chaldini Factors Recap

Oct 30, 2020 • 51min
#1 - What is a CISO?
On this pilot episode you will get to meet the hosts of the show (G Mark Hardy & Ross Young) and learn a little bit about their backgrounds.
Chapters
00:00 Introductions
04:47 What is a CISO?
07:24 Enable the Rock Climber to Take Risks
13:32 What do CISOs need to know?
18:07 Compliance is a C-
21:23 What functions and services do CISOs oversee?
25:48 The importance of a Purple Team
29:45 Is your Security Office a Red Team or a Blue Team?
34:50 Which organization in security is most likely to produce a CISO
39:11 The Hidden Key to Success is Communication Skills
41:17 CISO Key Capabilities are Communication and Influence
46:57 What are the skills you need to focus on


