CISO Tradecraft®
Episodes
#165 - Modernizing Our SOC Ingest (with JP Bourget)
22 Jan 2024
Contributed by Lukas
In this episode of CISO Tradecraft, host G Mark Hardy interviews JP Bourget about the security data pipeline and how modernizing SOC ingest can improv...
#164 - The 7 Lies in Cyber
15 Jan 2024
Contributed by Lukas
In this episode of CISO Tradecraft, we debunk seven common lies pervasive in the cybersecurity industry. From the fallacy of achieving a complete inve...
#163 - Operational Resilience
08 Jan 2024
Contributed by Lukas
Join G Mark Hardy in this episode of the CISO Tradecraft podcast where he details how cyber protects revenue. He clarifies how cybersecurity is seen a...
#162 - CISO Predictions for 2024
01 Jan 2024
Contributed by Lukas
Looking for accurate predictions on what 2024 holds for cybersecurity? Tune into our latest episode of CISO Tradecraft for intriguing insights and ind...
#161 - Secure Developer Training Programs (with Scott Russo) Part 2
25 Dec 2023
Contributed by Lukas
In the second half of the discussion about secure developer training programs, G Mark Hardy and Scott Russo delve deeper into how to engineer an effec...
#160 - Secure Developer Training Programs (with Scott Russo) Part 1
18 Dec 2023
Contributed by Lukas
In this episode of CISO Tradecraft, host G Mark Hardy invites Scott Russo, a cybersecurity and engineering expert for a deep dive into the creation an...
#159 - Refreshing Your Cybersecurity Strategy
11 Dec 2023
Contributed by Lukas
In this episode of CISO Tradecraft, host G. Mark Hardy guides listeners on how to refresh their cybersecurity strategy. Starting with the essential as...
#158 - Building a Data Security Lake (with Noam Brosh)
04 Dec 2023
Contributed by Lukas
Discover the key to a more effective cybersecurity strategy in the newest episode of CISO Tradecraft! We're talking SOC tools, building a data lake fo...
#157 - SOC Skills (with Hasan Eksi) Part 2
27 Nov 2023
Contributed by Lukas
In this episode of CISO Tradecraft, G Mark Hardy and Hasan Eksi from CyberNow Labs continue the discussion about the vital skills needed for an effect...
#156 - SMB CISO Challenges (with Kevin O’Connor)
20 Nov 2023
Contributed by Lukas
In this episode of CISO Tradecraft, host G Mark Hardy talks to Kevin O'Connor, the Director of Threat Research at Adlumin. They discuss the importance...
#155 - SOC Skills (with Hasan Eksi) Part 1
13 Nov 2023
Contributed by Lukas
In this episode of CISO Tradecraft we have a detailed conversation with Hasan Eksi from CyberNow Labs. G Mark and Hasan discuss the top 20 skills requ...
#154 - Data Protection (with Amer Deeba)
06 Nov 2023
Contributed by Lukas
In this episode of CISO Tradecraft, host G Mark Hardy welcomes special guest Amer Deeba, CEO and co-founder of Normalyze. They focus on the importance...
#153 - Game-Based Learning (with Andy Serwin & Eric Basu)
30 Oct 2023
Contributed by Lukas
On this episode we talk about the differences between Gamification and Game-Based Learning. We think you will enjoy hearing how Game-Based learning ge...
#152 - Speak My Language (with Andrew Chrostowski)
23 Oct 2023
Contributed by Lukas
Learn the language of the board with Andrew Chrostowski. In this episode we discuss the 3 major risk categories of opportunity risk, cybersecurity ris...
#151 - Cyber War
16 Oct 2023
Contributed by Lukas
On this episode we do a master class on cyber warfare. Learn the terminology. Learn the differences and similarities between kinetic and cyber warfare...
#150 - Measuring Results
09 Oct 2023
Contributed by Lukas
On this episode we discuss the measuring results cheat sheet from Justin Mecham. Key focuses include: Defining SMART Goals (Specific, Measurable...
#149 - Board Perspectives
02 Oct 2023
Contributed by Lukas
On this episode we discuss the four key roles Boards play in cybersecurity. Setting the company's vision and risk strategy Reviewing assessment result...
#148 - Threat Modeling (with Adam Shostack)
25 Sep 2023
Contributed by Lukas
On this episode we bring on the leading expert of threat modeling (Adam Shostack) to discuss the four questions that every team should ask: What are w...
#147 - Betting on MFA
18 Sep 2023
Contributed by Lukas
There's a lot of new cyber attacks occurring and today we are going to talk about them in more detail. Many bad actors are using SMS spoofing an...
#146 - Living in a Materiality World
11 Sep 2023
Contributed by Lukas
Have you ever thought about what does it mean to say there has been a material incident? How is materiality determined? What is the history of how tha...
#145 - The Cost of Cyber Defense
04 Sep 2023
Contributed by Lukas
On this episode we overview the CIS Document titled, "The Cost of Cyber Defense". https://www.cisecurity.org/insights/white-papers/the-cost-of-cyber-d...
#144 - Handling Regulatory Change
28 Aug 2023
Contributed by Lukas
In this episode of CISO Tradecraft, we delve into the evolving landscape of cybersecurity regulations. From data incident notifications to required co...
#143 - Authentication, Rainbow Tables, and Password Managers
21 Aug 2023
Contributed by Lukas
Here's a nice overview of cybersecurity on passwords, authentication, rainbow tables, and password managers. Enjoy the show and check out our other po...
#142 - Powerful Questions
14 Aug 2023
Contributed by Lukas
Join us at the heart of Hacker Summer Camp for insights into the cybersecurity world! Discover the art of asking powerful questions that can change yo...
#141 - Emerging Risks (with The Chertoff Group)
07 Aug 2023
Contributed by Lukas
On this episode, David London and Adam Isles from the Chertoff Group stop by to discuss emerging risk topics such as AI, Supply Chain Attacks, and the...
#140 - Bobby the Intern
31 Jul 2023
Contributed by Lukas
Don't let Bobby the Intern cause havoc in your network. On this episode of CISO Tradecraft, G Mark Hardy discusses the importance of training new hire...
#139 - Insider Threat Operations (with Jim Lawler)
24 Jul 2023
Contributed by Lukas
On this episode we bring on CIA Veteran James "Jim" Lawler to discuss how spies are recruited, how individuals are turned, and what makes them vulnera...
#138 - Updating the Mindmap (with Rafeeq Rehman)
17 Jul 2023
Contributed by Lukas
This week Rafeeq Rehman returns to discuss the 2023 updates to the CISO Mindmap. Note you can find his work here: https://rafeeqrehman.com/2023/03/25/...
#137 - 1% Better Leadership (with Andy Ellis)
10 Jul 2023
Contributed by Lukas
Imagine if you could get 1% better every day at something and do this for an entire year. Well, that's 365 days. And you go, okay, fine. 1%. 1%. That'...
#136 - From Hacking to Hardcover (with Bill Pollock)
03 Jul 2023
Contributed by Lukas
Are you a Chief Information Security Officer (CISO) looking to share your knowledge and insights with the world? In this episode, we explore how CISOs...
#135 - Board Decks (with Demetrios Lazarikos)
26 Jun 2023
Contributed by Lukas
One of the most important activities a CISO must perform is presenting high quality presentations to the Board of Directors. Listen and learn fr...
#134 - Ransomware Response (with Ricoh Danielson)
19 Jun 2023
Contributed by Lukas
A lot of times we focus on preventing ransomware, but we forget what we should do when we actually encounter it. That's why we are bringing on R...
#133 - The Seesaw of Cyber Recruiting (with Lee Kushner)
12 Jun 2023
Contributed by Lukas
This episode features Lee Kushner discussing various topics, including negotiating skills, the importance of degrees in the cybersecurity field, the n...
#132 - Founding to Funding (with Cyndi and Ron Gula)
05 Jun 2023
Contributed by Lukas
On this episode we bring in Cyndi and Ron Gula from Gula Tech (https://www.gula.tech/) to talk about their cyber security experiences. Listen and enjo...
#131 - Framing Executive Discussions
29 May 2023
Contributed by Lukas
How do we frame an executive discussion so we can structure and present information in a way that effectively engages and aligns with the needs and in...
#130 - Financial Planning (with Logan Jackson)
22 May 2023
Contributed by Lukas
Learn how to unlock financial success with key strategies by Logan Jackson from Ray Capital Advisors. Logan highlights how to set clear goals, c...
#129 - Protecting Your Family
15 May 2023
Contributed by Lukas
Are you looking for ways to protect your most valuable asset? In this episode, G Mark Hardy argues that our most valuable asset is our family, not the...
#128 - How do CISOs spend their time?
08 May 2023
Contributed by Lukas
In this episode of "CISO Tradecraft," G. Mark Hardy defines the role of a CISO and discusses the Top 10 responsibilities of a Chief Information Securi...
#127 - How to Stop Bad Guys from Staying on Your Network (with Kevin Fiscus)
01 May 2023
Contributed by Lukas
In this episode of CISO Tradecraft, G Mark Hardy and guest Kevin Fiscus discuss the challenges of cybersecurity and the importance of prioritizing sec...
#126 - ChatGPT & Generative AI (with Konstantinos Sgantzos)
24 Apr 2023
Contributed by Lukas
Have you heard about the latest trends in Generative Artificial Intelligence (GAI)? Listen to this episode of CISO Tradecraft to learn from Konstantin...
#125 - Cyber Ranges (with Debbie Gordon)
17 Apr 2023
Contributed by Lukas
Are you worried about cyber threats and data breaches? Do you want to build a strong cybersecurity program to protect your organization? Look no furth...
#124 - Simple, Easy, & Cheap Cybersecurity Measures (with Brent Deterding)
10 Apr 2023
Contributed by Lukas
Are you concerned about the security of your data? If so, you're in luck, because we have an incredible episode that has Brent Deterding discuss how t...
#123 - Accepted Cyber Strategy (with Branden Newman)
03 Apr 2023
Contributed by Lukas
In this episode of "CISO Tradecraft," G Mark Hardy discusses how to build an effective cyber strategy that executives will appreciate. He breaks down ...
#122 - Methodologies for Analysis (with Christopher Crowley)
27 Mar 2023
Contributed by Lukas
Sometimes you just need structure to the madness. Christopher Crowley stops by to talk about methodologies that can help security organizations. Come ...
#121 - Legal Questions (with Evan Wolff)
20 Mar 2023
Contributed by Lukas
Have you ever wanted to get a legal perspective on cybersecurity? On this episode of CISO Tradecraft, Evan Wolff stops by to discuss terms such ...
#120 - Negotiating Your Best CISO Package (with Michael Piacente)
13 Mar 2023
Contributed by Lukas
Have you ever wondered how to negotiate your best CISO compensation package? On this episode, we invite Michael Piacente from Hitch Partners to ...
#119 - Ethics (with Stephen Northcutt)
06 Mar 2023
Contributed by Lukas
One of the most difficult things to do as a manager or leader is to take an ethical stance on something you believe in. Sometimes ethical stance...
#118 - Data Engineering (with Gal Shpantzer)
27 Feb 2023
Contributed by Lukas
Our systems generate fantastic amounts of information, but do we have a complete understanding of how we collect, analyze, manage, store, and retrieve...
#117 - Good Governance (with Sameer Sait)
20 Feb 2023
Contributed by Lukas
Has bad governance given you trauma, boring committees, and long speeches on irrelevant issues? Today we are going to overcome that by talking a...
#116 - A European view of CISO responsibilities (with Michael Krausz)
13 Feb 2023
Contributed by Lukas
In the US we often focus on SOC-2, NIST Special Pubs, and the Cybersecurity Framework. In Europe (and most of the rest of the world), ISO 27001 is the...
#115 - The Business Case for a Global Lead of Field Cybersecurity (with Joye Purser)
06 Feb 2023
Contributed by Lukas
How can cyber best help the sales organization? It's a great thought exercise that we bring on Joye Purser to discuss. Learn from her experience...
#114 - One Vendor to Secure Them All
30 Jan 2023
Contributed by Lukas
Did you ever wonder how much security you can implement with a single vendor? We did and were surprised by how much you can do using the Austral...
#113 - SAST Security (with John Steven)
23 Jan 2023
Contributed by Lukas
This episode provides a deep dive into Static Application Security Testing (SAST) tools. Learn how they work, why they don't work as well as you...
#112 - Attack Surface Management (with Richard Ford)
17 Jan 2023
Contributed by Lukas
How do you defend against automated attacks in an era of ChatGPT-formulated malware, coordinated nation-state actors, and a host of disgruntled laid-o...
#111 - Leading with Style
09 Jan 2023
Contributed by Lukas
Have you ever wanted to be like Neo in "The Matrix" and learn things like Kung Fu in just a few minutes? Well on today's episode, we try to do j...
#110 - CISO Predictions for 2023
02 Jan 2023
Contributed by Lukas
Want to know CISO Tradecraft's Top 10 cyber security predictions for 2023? Listen to the episode to learn more about: Proactive Identity Managem...
#109 - The Right Stuff
19 Dec 2022
Contributed by Lukas
Success leaves clues, but sometimes we limit ourselves by only looking close by for them. This week, we pondered what business skills are essent...
#108 - Show Me The Money (with Nick Vigier)
12 Dec 2022
Contributed by Lukas
There's a lot of things you need to know as a CISO, but one of the things least taught is budgeting best practices. On today's episode, CISO Nic...
#107 - Consolidating Vulnerability Management (with Jeff Gouge)
05 Dec 2022
Contributed by Lukas
Special thanks to Jeff Gouge for sharing his thoughts on consolidating vulnerability management. We also thank our sponsor Nucleus Security for ...
#106 - How to Win Your First CISO Role
28 Nov 2022
Contributed by Lukas
Are You Ready To Win Your First CISO role? Apply these techniques into your resume and interview process so both recruiters and hiring managers will o...
#105 - Start Me Up (with Bob Cousins)
21 Nov 2022
Contributed by Lukas
Would you like to hear a master class on what Technology professionals need to know about startups? On this episode Bob Cousins stops by to...
#104 - Breach and Attack Simulation (with Dave Klein)
14 Nov 2022
Contributed by Lukas
Special Thanks to our podcast sponsor, Cymulate. On this episode, Dave Klein stops by to discuss the 3 Digital Challenges that organizations fac...
#103 - Listening to the Wise (with Bill Cheswick)
07 Nov 2022
Contributed by Lukas
Have you ever just met someone that was so interesting that you just sat and gave them your full attention? On this episode of CISO Tradecraft, ...
#102 - Mentorship, Sponsorship, and A Message to Garcia
31 Oct 2022
Contributed by Lukas
Hello, and welcome to another episode of CISO Tradecraft -- the podcast that provides you with the information, knowledge, and wisdom to be a more eff...
#101 - SaaS Security Posture Management (with Ben Johnson)
24 Oct 2022
Contributed by Lukas
Special Thanks to our podcast sponsor, Obsidian Security. We are really excited to share today’s show on SaaS Security Posture Managemen...
#100 - 7 Ways CISOs Setup for Success
17 Oct 2022
Contributed by Lukas
References https://github.com/cisotradecraft/Podcast https://cisotradecraft.podbean.com/e/84-gaining-trust-with-robin-dreeke/ https://www.youtube.com/...
#99 - Cyberwar and the Law of Armed Conflict (with Larry Dietz)
10 Oct 2022
Contributed by Lukas
Episode 99 - Cyberwar and the Law of Armed Conflict with Larry Dietz We bring you another episode from Naas, Ireland today speaking about cyberwar an...
#98 - Outrunning the Bear
03 Oct 2022
Contributed by Lukas
Hello, and welcome to another episode of CISO Tradecraft -- the podcast that provides you with the information, knowledge, and wisdom to be a more eff...
#97 - Mobile Application Security (with Brian Reed)
26 Sep 2022
Contributed by Lukas
Special Thanks to our podcast sponsor, NowSecure. On this episode, Brian Reed (Chief Mobility Officer at NowSecure) stops in to provide a world ...
#96 - The 9 Cs of Cyber
19 Sep 2022
Contributed by Lukas
Ahoy! and welcome to another episode of CISO Tradecraft -- the podcast that provides you with the information, knowledge, and wisdom to be a more effe...
#95 - Got any Data Security (with Brian Vecci)
12 Sep 2022
Contributed by Lukas
Special Thanks to our podcast Sponsor, Varonis. Please check out Varonis's Webpage to learn more about their custom data security solutions and ...
#94 - Easier, Better, Faster, & Cheaper Software
05 Sep 2022
Contributed by Lukas
Hello, and welcome to another episode of CISO Tradecraft, the podcast that provides you with the information, knowledge, and wisdom to be a more effec...
#93 - How to Become a Cyber Security Expert
29 Aug 2022
Contributed by Lukas
How do you become a Cyber Security Expert? Hello and welcome to another episode of CISO Tradecraft, the podcast that provides you with the information...
#92 - Updating the Executive Leadership Team on Cyber
22 Aug 2022
Contributed by Lukas
Show Notes Hello, and welcome to another episode of CISO Tradecraft -- the podcast that provides you with the information, knowledge, and wisdom to be...
#91 - Hacker Summer Camp
15 Aug 2022
Contributed by Lukas
On this episode you can hear the tale of three conferences. Listen and learn about the history of BSides, Black Hat, and DEF CON. Learn wh...
#90 - A CISO’s Guide to Pentesting
08 Aug 2022
Contributed by Lukas
A CISO’s Guide to Pentesting References https://en.wikipedia.org/wiki/Penetration_test https://partner-security.withgoogle.com/docs/pentest_guidelin...
#89 - Connecting the Dots (with Sean Heritage)
01 Aug 2022
Contributed by Lukas
I've been a fan of Sean Heritage for years when I first discovered his blog, "Connecting the Dots." Today I have the privilege to listen to...
#88 - Tackling 3 Really Hard Problems in Cyber (with Andy Ellis)
25 Jul 2022
Contributed by Lukas
This episode of CISO Tradecraft, Andy Ellis from Orca Security stops by to talk about three really hard problems that CISOs have struggled with for de...
#87 - From Hunt Team to Hunter (with Bryce Kunz)
18 Jul 2022
Contributed by Lukas
On this episode of CISO Tradecraft, Bryce Kunz from Stage 2 Security stops by to discuss how offensive cyber operations are evolving. Come and l...
#86 - The CISO MindMap (with Rafeeq Rehman)
11 Jul 2022
Contributed by Lukas
This episode features Rafeeq Rehman. He discusses the need for a CISO Mindmap and 6 Focus Areas for 2022-2023: 1. Re-evaluate ransomw...
#85 - The Fab 5 Security Outcomes Study (with Helen Patton)
04 Jul 2022
Contributed by Lukas
On this episode of CISO Tradecraft, we feature Helen Patton. Helen shares many of her career experiences working across JP Morgan, The Ohio State Univ...
#84 - Gaining Trust (with Robin Dreeke)
27 Jun 2022
Contributed by Lukas
On this episode of CISO Tradecraft we feature Robin Dreeke from People Formula. Robin was the former head of the FBI Counterintelligence Behavio...
#83 - Cyber Defense Matrix Reloaded (with Sounil Yu)
20 Jun 2022
Contributed by Lukas
This episode is sponsored by Varonis. You can learn more on how to reduce your ransomware radius by performing a free ransomware readiness ...
#82 - Cyber Defense Matrix (with Sounil Yu)
13 Jun 2022
Contributed by Lukas
This episode is sponsored by Varonis. You can learn more on how to reduce your ransomware radius by performing a free ransomware readiness asses...
#81- Career Lessons from a CISO (with John Hellickson)
06 Jun 2022
Contributed by Lukas
On this episode of CISO Tradecraft, John Hellickson from Coalfire talks about his career as a CISO. Listen and learn about: The evolving role of...
#80 - Breaking Backbones (with Deb Radcliff)
30 May 2022
Contributed by Lukas
A respected journalist focusing on cybersecurity and our community of people for over 25 years, Deb Radcliff remains a trusted information source who ...
#79 - Addressing the Top CEO Concerns
23 May 2022
Contributed by Lukas
On this Episode of CISO Tradecraft we talk about the Top 10 areas of concern for the C Suite about Ransomware. Note you can read the full ISC2 S...
#78 - Business Objectives & 5 CISO Archetypes (with Christian Hyatt)
16 May 2022
Contributed by Lukas
On this episode of CISO Tradecraft, Christian Hyatt from risk3sixty stops by to discuss the 3 major Business Objectives for CISOs: Risk Management Cos...
#77 - Countering Corporate Espionage
09 May 2022
Contributed by Lukas
Chances are your organization has information that someone else wants. If it's another nation state, their methods may not be friendly or e...
#76 - The Demise of the Cybersecurity Workforce
02 May 2022
Contributed by Lukas
Our career has been growing like crazy with an estimated 3.5 million unfilled cybersecurity jobs within the next few years. More certs, mor...
#75 - Avoiding Death By PowerPoint
25 Apr 2022
Contributed by Lukas
On this episode of CISO Tradecraft, we discuss how to avoid Death By PowerPoint by creating cyber awareness training that involves and engages listene...
#74 - Pass the Passwords
18 Apr 2022
Contributed by Lukas
On this episode of CISO Tradecraft, we focus on the Password Security and how it's evolving. Tune in to learn about: Why do we need passwords Wa...
#73 - Wonderful Winn Schwartau
11 Apr 2022
Contributed by Lukas
Winn Schwartau is a well-recognized icon in the cybersecurity community, and also a dear friend for over 25 years. Always one to stir the pot an...
#72 - Logging In with SIEMs (with Anton Chuvakin)
04 Apr 2022
Contributed by Lukas
On this episode of CISO Tradecraft, Anton Chuvakin talks about Logging, Security Information & Event Management (SIEM) tooling, and Cloud Security. &n...
#71 - Lessons Learned as a CISO (with Gary Hayslip)
28 Mar 2022
Contributed by Lukas
On this special episode of CISO Tradecraft, we have Gary Hayslip talk about his lessons learned being a CISO. He shares various tips and tricks ...
#70 - Partnership is Key
21 Mar 2022
Contributed by Lukas
On this episode of CISO Tradecraft you can learn how to build relationships of trust with other executives by demonstrating executive skill & cyber se...
#69 - Aligning Security Initiatives with Business Objectives
14 Mar 2022
Contributed by Lukas
On this episode of CISO Tradecraft, we talk about how cyber can help the four business key objectives identified by InfoTech: 1. Profit generati...
#68 - Thought Provoking Discussions (with Richard Thieme)
07 Mar 2022
Contributed by Lukas
Today we speak with Richard Thieme, a man with a reputation for stretching your mind with his insights, who has spoken at 25 consecutive DEFCONs ...
#67 - Knock, Knock? Who’s There and Whatcha Want?
28 Feb 2022
Contributed by Lukas
On this episode of CISO Tradecraft we are going to talk about various Access Control & Authentication technologies. Access Control Methodologies: Mand...
#66 - Working On The Supply Chain Gang
21 Feb 2022
Contributed by Lukas
On this episode of CISO Tradecraft, you can learn about supply chain vulnerabilities and the 6 important steps you can take to mitigate this attack wi...