Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing
Podcast Image

CISO Series Podcast

It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

23 Jun 2026

Transcription

Transcript generated automatically by AI and may contain errors.

Chapter 1: What advice do CISOs need when starting in a new role?

0.031 - 2.295

Best advice for a CISO. Go.

0

2.976 - 22.067 Megan Samford

Get a third-party independent report. If you're coming into a company, new to a program, new to a role, you want to make a big splash in the first six months, get a third-party report to baseline where your program's at. And that's something that you can immediately hand off and present to your board. And that's going to add a lot of credibility to whatever strategy you're trying to form.

0

23.77 - 26.815

It's time to begin the CISO Series podcast.

0

37.055 - 53.834 David Spark

Welcome to the CISO Series podcast. My name is David Spark. I am the producer of said CISO Series and joining me as my co-host for this very episode. It's one of your favorites. You tell me it's one of your favorites. It's Andy Ellis, principal for DUHA. Andy, say hello to the audience.

0

54.275 - 72.182 Andy Ellis

Dobre popolodnie, alebo zavislosti od toho, keri sa nazvete, nachadze date, dobre rano, dobre vecer, alebo dobru noc. That would be Slovak in honor of we are recording during the Olympics, and tomorrow the U.S. team will be playing Slovakia in hockey.

72.603 - 79.617 David Spark

Well, by the time everyone hears this, it'll be months past. I know. And we will know who won that.

79.597 - 90.208 Andy Ellis

But my mother-in-law was born in, it was the time was Czechoslovakia, but on the Slovak side. So we're going to be doing a watch party together with them, I think, tomorrow or three months ago, depending on how you think about it.

91.009 - 109.369 David Spark

Audience, we are available also at CISOseries.com where you can find all of our other wonderful programming. So you should spend, I would say, one to two hours. That's what, you know, most professional doctors order. One to two hours of CISO Series a day. I would strongly recommend it. Our sponsor for today's episode is Native Security.

110.05 - 136.857 David Spark

Unify, manage, and maximize built-in cloud security controls and achieve secure by design consistency across cloud environments. That is Native Security. And we're going to talk more about that later in the show. But first, Andy. I want to talk about actually a quote that I saw, that I posted, that there was a certain phrase in this quote that both hit us.

Chapter 2: How do the roles of watchmaker and gardener differ in cybersecurity?

422.75 - 444.117 Andy Ellis

but it's mostly the gardener mode. Like if you're gonna say the watchmaker's obsessing over policy, like policy is a reflection of culture. And the problem that most people have is they think it goes the other direction. People who write policy think you can change culture by policy. You can't. You change culture by having tools that work, and then you write policy to match your tools that work.

0

444.097 - 453.551 Andy Ellis

And so if you're going to make me pick one, I'm going to say I want to be the gardener because I'm obsessing over how my policy is a reflection of culture. But I change culture before I change policy.

0

454.332 - 468.653 David Spark

All right. Very good. I take this one to you, Megan. Yes, I would agree that most CISOs are gardeners cultivating a team, but you have to kind of lean into the watchmaker. What do you think, Megan?

0

469.122 - 488.411 Megan Samford

Yeah, I think it's really more about achieving the balance between high alignment and high autonomy, right? And for large organizations, what I've seen work successfully is this concept of a three lines of defense strategy. So the first line of defense needs to be where the risk actually originates.

0

488.431 - 509.743 Megan Samford

So if you're a company like mine that develops products and sells them to global markets, our first line of defense is typically considered developers and divisions and individual P&Ls unto themselves. And so that's really where the risk originates. It's the best opportunity you have to mitigate that risk directly. The key thing with the first line of defense is that

509.723 - 529.858 Megan Samford

Anyone in the first line of defense, just like a factory floor from the 1970s, they should be empowered to have what's called stop the line capability. If anyone observes behavior that is out of bounds for the company's values, for their policies, what it clearly says we're going to do with our secure development lifecycle and the way that we make products,

529.838 - 544.937 Megan Samford

anyone should be empowered to raise their hand and say, I don't agree with this behavior and this needs to be looked at more thoroughly. That being said, there's also the second line of defense. That's really where CISOs sit is the second line of defense. We are risk overseers.

545.437 - 568.053 Megan Samford

And so our job is to set policies, set successful governance structures, empower that first line of defense, make their lives easier, create clear escalation paths when we're not seeing behavior that we wanna see How did the right folks get eyes on it? And how is that risk disposition properly with escalations that hopefully don't need to have emotion about them, right?

568.093 - 576.231 Megan Samford

When things are going wrong, everyone should be free to say that this is something that we need to take a closer look at. But you're really running more like air traffic control.

Chapter 3: What is the economic argument for secure code?

1523.67 - 1529.301 David Spark

You don't have enough staff. You don't have the tooling. You're like, who knows what the heck it is that you can't, but you just can't deal with it.

0

1529.321 - 1553.044 Andy Ellis

But where Megan is, Megan is in my sort of ideal state on that first one, which is ultimately the job of the CISO is not to fix risk. There are small places where we own fixing risks. But most of what we do is incentivize the rest of the business to do so. If the rest of the business chooses not to do so, but the CEO and the board is aware of that and is fine with that, you have done your job.

0

1553.745 - 1566 Andy Ellis

Like the single biggest stressor in the CISO world is the belief that you get to decide what risks get closed. And you don't, that's the business's job. And Megan's saying, I'm good with that.

0

1566.065 - 1566.426 Megan Samford

Yes.

0

1566.786 - 1568.269 Andy Ellis

All right, Megan, which one are you choosing?

1568.289 - 1569.651 David Spark

Which one's the worst scenario then?

1570.112 - 1570.853 Andy Ellis

She took number two.

1570.893 - 1574.018 Megan Samford

Yeah, I took number two, but I mean, I don't.

1574.058 - 1575.902 David Spark

So you disagree with Andy. So that's great.

Comments

There are no comments yet.

Please log in to write the first comment.