
CISO Tradecraft®
Welcome to CISO Tradecraft®, your guide to mastering the art of being a top-tier Chief Information Security Officer (CISO). Our podcast empowers you to elevate your information security skills to an executive level. Join us on this journey through the domains of effective CISO leadership.
© Copyright 2025, National Security Corporation. All Rights Reserved
Latest episodes

Sep 23, 2024 • 28min
#199 - How to Secure Generative AI
G. Mark Hardy, a security expert focused on Generative AI, discusses critical insights on securing these emerging technologies. He unpacks the mechanics of large language models like ChatGPT and highlights major industry players. G. Mark delves into the risks of AI misuse, including data breaches and fabricated content. He offers practical strategies for CISOs to mitigate these threats, emphasizing the CARE standard for effective governance. Additionally, he touches on the future vulnerabilities of AI and the need for ethical guidelines to foster responsible innovation.

Sep 16, 2024 • 22min
#198 - Securing the Business Processes
G Mark Hardy, a cybersecurity strategist from Glasgow, shares his expertise on securing vital business processes. He emphasizes the necessity for leaders to communicate the real impact of vulnerabilities. The discussion includes insights on the CIA triad and the importance of identifying critical processes like billing and shipping. Hardy also covers decision-making during crises, highlighting the need for effective planning and training. His practical advice aims to strengthen organizational resilience against potential cybersecurity threats.

Sep 9, 2024 • 46min
#197 - Fedshark's Blueprint for Cost Effective Risk Reduction
Join host G Mark Hardy as he dives deep into the complexities of compliance and reporting, featuring special guests Brian Bradley and Josh Williams from FedShark. Discover a unique and streamlined approach to compliance using FedShark's innovative tools and AI-assisted systems. Learn about their exclusive offers for CISO Tradecraft listeners, including free downloads and discounted pre-assessment tools. Topics covered include CMMC, HIPAA, PCI, and more. Whether you're part of the Defense Industrial Base or dealing with multiple compliance frameworks, this episode is packed with practical advice to make your compliance journey smoother and more effective.
Thanks to our podcast sponsor, Fedshark
CISO Traderaft Promo & Link to CMMC White Papers: https://fedshark.com/ciso
RapidAssess: https://fedshark.com/rapid-assess
Company website: https://fedshark.com
FedShark Blog: https://fedshark.com/blog
Schedule a Demo: https://fedshark.com/contact-us
LinkedIn Matt Beaghley: https://www.linkedin.com/in/mbeaghley/
LinkedIn Brian Bradley: https://www.linkedin.com/in/brian-bradley-97a82668/
Chapters
00:00 Introduction and Special Offer
03:18 Meet the Experts: Brian and Josh
06:49 Challenges in Compliance
16:23 Understanding CMMC
29:02 Understanding Scope in Compliance
30:22 Introducing the AI-Enhanced Compliance Solution
31:24 Streamlining Interviews and Documentation
42:19 Final Thoughts and Recommendations

Sep 2, 2024 • 47min
#196 - Cyber Thrills and Author Quills (with Deb Radcliff)
Deb Radcliff, author of the 'Breaking Backbones' trilogy, dives into the world of cybersecurity with G Mark Hardy. They share insights from Black Hat, revealing the evolving nature of security conferences and the balance between networking and education. Deb discusses intriguing topics like AI's role in cybersecurity, the ethical dilemmas of drones in warfare, and the challenges authors face in capturing the complexity of cyber conflicts. This conversation blends thrilling storytelling techniques with serious industry concerns, making it a captivating listen.

Aug 26, 2024 • 48min
#195 - Pentesting for Readiness not Compliance (with Snehal Antani)
In this episode of CISO Tradecraft, host G Mark Hardy is joined by special guest Snehal Antani, co-founder of Horizon3.AI, to discuss the crucial interplay between offensive and defensive cybersecurity tactics. They explore the technical aspects of how observing attacker behavior can enhance defensive strategies, why traditional point-in-time pen testing may be insufficient, and how autonomous pen testing can offer continuous, scalable solutions. The conversation delves into Snehal’s extensive experience, the importance of readiness over compliance, and the future of cybersecurity tools designed with humans out of the loop. Tune in to learn how to elevate your cybersecurity posture in a rapidly evolving threat landscape.
Horizon3 - https://www.horizon3.ai
Snehal Antani - https://www.linkedin.com/in/snehalantani/
Transcripts: https://docs.google.com/document/d/1IFSQ8Uoca3I7TLqNHMkvm2X-RHk8SWpo
Chapters:
00:00 Introduction and Guest Welcome
01:43 Background and Experience of Snehal Antani
03:09 Challenges and Limitations of Traditional Pen Testing
14:47 The Future of Pen Testing: Autonomous Systems
23:10 Leveraging Data for Cybersecurity Insights
24:02 Expanding the Attack Surface: Cloud and Supply Chain
24:46 Third-Party Risk Management Evolution
44:37 Future of Cyber Warfare: Algorithms vs. Humans

Aug 19, 2024 • 39min
#194 - The IAM Masterclass
In this episode of CISO Tradecraft, host G Mark Hardy delves into the intricate world of Identity and Access Management (IAM). Learn the essentials and best practices of IAM, including user registration, identity proofing, directory services, identity federation, credential issuance, and much more. Stay informed about the latest trends like proximity-based MFA and behavioral biometrics. Understand the importance of effective IAM implementation for safeguarding sensitive data, compliance, and operational efficiency. Plus, hear real-world examples and practical advice on improving your IAM strategy for a secure digital landscape.
Transcripts: https://docs.google.com/document/d/15zUupqhCQz9llwy21GW5cam8qXgK80JB
Chapters
00:00 Introduction to CISO Tradecraft
01:24 Understanding Identity and Access Management (IAM)
01:54 Gartner's Magic Quadrant and IAM Vendors
03:29 The Importance of IAM in Enterprises
04:28 User Registration and Verification
06:48 Password Policies and Best Practices
09:53 Identity Proofing Techniques
14:53 Directory Services and Role Management
18:27 Identity Federation and Credential Issuance
22:22 Profile and Role Management
26:17 Identity Lifecycle Management
29:23 Access Management Essentials
35:05 Review and Conclusion

Aug 12, 2024 • 43min
#193 - Security Team Operating System (with Christian Hyatt)
In this comprehensive episode of CISO Tradecraft, host G Mark Hardy sits down with Christian Hyatt, author of 'The Security Team Operating System'. Together, they delve into the five essential components needed to transform your cyber security team from reactive to unstoppable. From defining purpose and values to establishing clear roles, rhythms, and goals, this podcast offers practical insights and tools that can improve the efficacy and culture of your security team. If you're looking for strategic frameworks to align your team with business objectives and create a resilient security culture, you won't want to miss this episode!
Christian Hyatt's LinkedIn Profile: https://www.linkedin.com/in/christianhyatt/
Link to the Book: https://a.co/d/aHpXXfr
Transcripts: https://docs.google.com/document/d/1ogBdtJolBJTOVtqyFLO5onuLxBsfqqQP
Chapters
00:00 Introduction and Guest Welcome
01:31 Overview of the Security Team Operating System
03:31 Deep Dive into the Five Elements
07:53 Aligning Security with Business Objectives
21:59 Defining Core Values for Security Teams
25:03 Aligning Organizational and Team Values
26:05 Establishing Clear Roles and Responsibilities
30:58 Implementing Effective Rhythms and Goals

Aug 5, 2024 • 45min
#192 - From Cyber Burnout to VCISO Bliss (with Olivia Rose)
Join host G Mark Hardy in this episode of CISO Tradecraft as he welcomes Olivia Rose, an experienced CISO and founder of the Rose CISO Group. Olivia discusses her journey in cybersecurity from her start in marketing to becoming a VCISO. They delve into key topics including the transition from CISO to VCISO, strategies for managing time and stress, the importance of understanding board dynamics, and practical advice on mentoring new entrants in the cybersecurity field. Olivia also shares her insights on maintaining business alignment, handling insurance as a contractor, and building a personal brand in the cybersecurity community.
Olivia Rose: https://www.linkedin.com/in/oliviarosecybersecurity/
Transcripts: https://docs.google.com/document/d/1S42BepIh1QQHVWsdhhgx6x99U188q5eL
Chapters
00:00 Introduction and Guest Welcome
01:14 Olivia Rose's Career Journey
06:42 Challenges in Cybersecurity Careers
15:47 Communicating with the Board
22:57 Navigating Compliance and Legal Challenges
24:10 Building Strategic Relationships
25:46 Aligning Security with Business Goals
35:05 The Importance of Reputation and Branding

Jul 29, 2024 • 45min
#191 - From Breach to Bench (with Thomas Ritter)
In this episode of CISO Tradecraft, host G Mark Hardy continues an in-depth discussion with cybersecurity attorney Thomas Ritter on the legal considerations for cybersecurity leaders. The episode touches on essential topics such as immediate legal steps after a data breach, the importance of using correct terminology, understanding attorney-client privilege and discovery, GDPR's impact, data localization, and proactive measures CISOs should take. The conversation also explores the implications of evolving cybersecurity laws and regulations like the Digital Operations Resilience Act and the potential criminal liabilities for CISOs.
Thomas Ritter: https://www.linkedin.com/in/thomas-ritter-2b91014a/
Transcripts: https://docs.google.com/document/d/15xQINUOdziGdcEFfh5SN8lS7svtK0JCT
Chapters
00:00 Introduction and Recap of Part 1
01:43 Starting the Discussion: Data Breaches
02:22 Legal Steps After a Data Breach
07:19 Understanding Attorney-Client Privilege
08:21 Discovery in Legal Cases
13:31 Staying Updated on Cybersecurity Laws
19:38 Impact of GDPR on Cybersecurity
32:00 Data Localization Challenges
34:55 Proactive Legal Preparedness
37:23 Final Thoughts and Conclusion

Jul 22, 2024 • 45min
#190 - Lawyers, Breaches, and CISOs: Oh My (with Thomas Ritter)
In this episode of CISO Tradecraft, host G Mark Hardy interviews cybersecurity lawyer Thomas Ritter. They discuss key legal topics for CISOs, including regulatory compliance, managing third-party risk, responding to data breaches, and recent legislative impacts. Thomas shares his journey into cybersecurity law and provides practical advice and real-world examples. Key points include the challenges of keeping up with evolving regulations, the intricacies of vendor management, and the implications of recent Supreme Court rulings. They also touch on major breaches like SolarWinds and Colonial Pipeline, exploring lessons learned and the importance of implementing essential security controls.
Thomas Ritter - https://www.linkedin.com/in/thomas-ritter-2b91014a/ Transcripts: https://docs.google.com/document/d/1EvZ_dOpFOLCSSv5ffqxCoMnLZDOnUv_K
Chapters
00:00 Introduction to CISO Tradecraft
00:48 Meet Thomas Ritter: Cybersecurity Lawyer
03:48 Legal Challenges for CISOs
04:54 Managing Third-Party Risks
13:01 Understanding Legal and Statutory Obligations
15:57 Supreme Court Rulings and Cybersecurity
32:57 Lessons from High-Profile Cyber Attacks
38:32 Ransomware Epidemic and Law Enforcement
43:30 Conclusion and Contact Information
Remember Everything You Learn from Podcasts
Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.