

CISO Tradecraft®
CISO Tradecraft®
Welcome to CISO Tradecraft®, your guide to mastering the art of being a top-tier Chief Information Security Officer (CISO). Our podcast empowers you to elevate your information security skills to an executive level. Join us on this journey through the domains of effective CISO leadership.
© Copyright 2025, National Security Corporation. All Rights Reserved
© Copyright 2025, National Security Corporation. All Rights Reserved
Episodes
Mentioned books

Oct 14, 2024 • 45min
#202 - Cybersecurity Crisis: Are We Failing the Next Generation?
In this episode of CISO Tradecraft, host G Mark Hardy explores the challenges and misconceptions facing the next generation of cybersecurity professionals. The discussion covers the myth of a talent shortage, the shortcomings of current educational and certification programs, and the significance of aligning curricula with real-world needs. Hardy emphasizes the importance of hands-on experience, developing soft skills, and fostering continuous learning. The episode also highlights strategies for retaining talent, promoting internal training, and creating leadership opportunities to cultivate a skilled and satisfied cybersecurity workforce.
Transcripts: https://docs.google.com/document/d/12fI2efHXuHR4dS3cu7P0UIBCtjBdgREI
Chapters
00:00 Introduction to the Cybersecurity Talent Crisis
00:40 Debunking the Talent Shortage Myth
02:23 The Real Talent Gap: Mid-Career Professionals
03:04 Outsourcing and Its Impact on Entry-Level Jobs
08:29 Challenges in Cybersecurity Education
16:13 The Importance of Practical Skills Over Theory
23:52 The Importance of Writing Skills
25:10 Continuous Learning and Self-Investment
26:07 Performance and Career Progression
28:40 Mentorship and Onboarding
29:51 Training and Development Challenges
32:32 Retention Strategies
33:44 Engaging Junior Employees
39:07 Technology and Innovation
40:54 Conclusion and Final Thoughts

Oct 7, 2024 • 18min
#201 - Avoiding Hurricanes in the Cloud
In this episode of CISO Tradecraft, hosted by G Mark Hardy, you'll learn about four crucial tools in cloud security: CNAPP, CASB, CSPM, and CWPP. These tools serve various functions like protecting cloud-native applications, managing access security, maintaining cloud posture, and securing cloud workloads. The discussion covers their roles, benefits, key success metrics, and best practices for CISOs. As the cloud security landscape evolves, understanding and integrating these tools is vital for keeping your organization safe against cyber threats.
Transcripts: https://docs.google.com/document/d/1Mx9qr30RuWrDUw1TLNkUDQ8xo4xvQdP_
Chapters
00:00 Introduction to Cloud Security Tools
02:24 Understanding CNAPP: The Comprehensive Cyber Defense
08:13 Exploring CASB: The Cloud Access Gatekeeper
11:12 Diving into CSPM: Ensuring Cloud Compliance
13:40 CWPP: Protecting Cloud Workloads
15:08 Best Practices for Cloud Security
15:54 Conclusion and Final Thoughts

9 snips
Sep 30, 2024 • 45min
#200 - Copywriting AI (with Mark Rasch)
Mark Rasch, an attorney specializing in AI and cybersecurity, dives into the intricate legal landscape shaped by artificial intelligence. He discusses copyright challenges with AI-generated content and emphasizes the importance of training data. The conversation delves into ethical dilemmas, such as the decision-making in AI within critical fields like healthcare and self-driving cars. Rasch also highlights how biases in data can affect AI outcomes and the implications for information security policy. Tune in for a compelling exploration of AI's legalities and ethical considerations!

11 snips
Sep 23, 2024 • 28min
#199 - How to Secure Generative AI
G. Mark Hardy, a security expert focused on Generative AI, discusses critical insights on securing these emerging technologies. He unpacks the mechanics of large language models like ChatGPT and highlights major industry players. G. Mark delves into the risks of AI misuse, including data breaches and fabricated content. He offers practical strategies for CISOs to mitigate these threats, emphasizing the CARE standard for effective governance. Additionally, he touches on the future vulnerabilities of AI and the need for ethical guidelines to foster responsible innovation.

Sep 16, 2024 • 22min
#198 - Securing the Business Processes
G Mark Hardy, a cybersecurity strategist from Glasgow, shares his expertise on securing vital business processes. He emphasizes the necessity for leaders to communicate the real impact of vulnerabilities. The discussion includes insights on the CIA triad and the importance of identifying critical processes like billing and shipping. Hardy also covers decision-making during crises, highlighting the need for effective planning and training. His practical advice aims to strengthen organizational resilience against potential cybersecurity threats.

5 snips
Sep 9, 2024 • 46min
#197 - Fedshark's Blueprint for Cost Effective Risk Reduction
Join host G Mark Hardy as he dives deep into the complexities of compliance and reporting, featuring special guests Brian Bradley and Josh Williams from FedShark. Discover a unique and streamlined approach to compliance using FedShark's innovative tools and AI-assisted systems. Learn about their exclusive offers for CISO Tradecraft listeners, including free downloads and discounted pre-assessment tools. Topics covered include CMMC, HIPAA, PCI, and more. Whether you're part of the Defense Industrial Base or dealing with multiple compliance frameworks, this episode is packed with practical advice to make your compliance journey smoother and more effective.
Thanks to our podcast sponsor, Fedshark
CISO Traderaft Promo & Link to CMMC White Papers: https://fedshark.com/ciso
RapidAssess: https://fedshark.com/rapid-assess
Company website: https://fedshark.com
FedShark Blog: https://fedshark.com/blog
Schedule a Demo: https://fedshark.com/contact-us
LinkedIn Matt Beaghley: https://www.linkedin.com/in/mbeaghley/
LinkedIn Brian Bradley: https://www.linkedin.com/in/brian-bradley-97a82668/
Chapters
00:00 Introduction and Special Offer
03:18 Meet the Experts: Brian and Josh
06:49 Challenges in Compliance
16:23 Understanding CMMC
29:02 Understanding Scope in Compliance
30:22 Introducing the AI-Enhanced Compliance Solution
31:24 Streamlining Interviews and Documentation
42:19 Final Thoughts and Recommendations

Sep 2, 2024 • 47min
#196 - Cyber Thrills and Author Quills (with Deb Radcliff)
Deb Radcliff, author of the 'Breaking Backbones' trilogy, dives into the world of cybersecurity with G Mark Hardy. They share insights from Black Hat, revealing the evolving nature of security conferences and the balance between networking and education. Deb discusses intriguing topics like AI's role in cybersecurity, the ethical dilemmas of drones in warfare, and the challenges authors face in capturing the complexity of cyber conflicts. This conversation blends thrilling storytelling techniques with serious industry concerns, making it a captivating listen.

Aug 26, 2024 • 48min
#195 - Pentesting for Readiness not Compliance (with Snehal Antani)
In this episode of CISO Tradecraft, host G Mark Hardy is joined by special guest Snehal Antani, co-founder of Horizon3.AI, to discuss the crucial interplay between offensive and defensive cybersecurity tactics. They explore the technical aspects of how observing attacker behavior can enhance defensive strategies, why traditional point-in-time pen testing may be insufficient, and how autonomous pen testing can offer continuous, scalable solutions. The conversation delves into Snehal’s extensive experience, the importance of readiness over compliance, and the future of cybersecurity tools designed with humans out of the loop. Tune in to learn how to elevate your cybersecurity posture in a rapidly evolving threat landscape.
Horizon3 - https://www.horizon3.ai
Snehal Antani - https://www.linkedin.com/in/snehalantani/
Transcripts: https://docs.google.com/document/d/1IFSQ8Uoca3I7TLqNHMkvm2X-RHk8SWpo
Chapters:
00:00 Introduction and Guest Welcome
01:43 Background and Experience of Snehal Antani
03:09 Challenges and Limitations of Traditional Pen Testing
14:47 The Future of Pen Testing: Autonomous Systems
23:10 Leveraging Data for Cybersecurity Insights
24:02 Expanding the Attack Surface: Cloud and Supply Chain
24:46 Third-Party Risk Management Evolution
44:37 Future of Cyber Warfare: Algorithms vs. Humans

7 snips
Aug 19, 2024 • 39min
#194 - The IAM Masterclass
In this episode of CISO Tradecraft, host G Mark Hardy delves into the intricate world of Identity and Access Management (IAM). Learn the essentials and best practices of IAM, including user registration, identity proofing, directory services, identity federation, credential issuance, and much more. Stay informed about the latest trends like proximity-based MFA and behavioral biometrics. Understand the importance of effective IAM implementation for safeguarding sensitive data, compliance, and operational efficiency. Plus, hear real-world examples and practical advice on improving your IAM strategy for a secure digital landscape.
Transcripts: https://docs.google.com/document/d/15zUupqhCQz9llwy21GW5cam8qXgK80JB
Chapters
00:00 Introduction to CISO Tradecraft
01:24 Understanding Identity and Access Management (IAM)
01:54 Gartner's Magic Quadrant and IAM Vendors
03:29 The Importance of IAM in Enterprises
04:28 User Registration and Verification
06:48 Password Policies and Best Practices
09:53 Identity Proofing Techniques
14:53 Directory Services and Role Management
18:27 Identity Federation and Credential Issuance
22:22 Profile and Role Management
26:17 Identity Lifecycle Management
29:23 Access Management Essentials
35:05 Review and Conclusion

Aug 12, 2024 • 43min
#193 - Security Team Operating System (with Christian Hyatt)
In this comprehensive episode of CISO Tradecraft, host G Mark Hardy sits down with Christian Hyatt, author of 'The Security Team Operating System'. Together, they delve into the five essential components needed to transform your cyber security team from reactive to unstoppable. From defining purpose and values to establishing clear roles, rhythms, and goals, this podcast offers practical insights and tools that can improve the efficacy and culture of your security team. If you're looking for strategic frameworks to align your team with business objectives and create a resilient security culture, you won't want to miss this episode!
Christian Hyatt's LinkedIn Profile: https://www.linkedin.com/in/christianhyatt/
Link to the Book: https://a.co/d/aHpXXfr
Transcripts: https://docs.google.com/document/d/1ogBdtJolBJTOVtqyFLO5onuLxBsfqqQP
Chapters
00:00 Introduction and Guest Welcome
01:31 Overview of the Security Team Operating System
03:31 Deep Dive into the Five Elements
07:53 Aligning Security with Business Objectives
21:59 Defining Core Values for Security Teams
25:03 Aligning Organizational and Team Values
26:05 Establishing Clear Roles and Responsibilities
30:58 Implementing Effective Rhythms and Goals