CISO Series Podcast

David Spark, Mike Johnson, and Andy Ellis

  • 39 minutes 59 seconds
    Back in My Day, You Could Get a Cybersecurity Job at the Corner Store

    All links and images can be found on CISO Series

    This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining is Paul Drapeau, head of global information security, New Balance.

    In this episode:

    • The logo trap
    • Immunity through exposure
    • The synthesis edge
    • The cost of holding tight

    A huge thanks to our sponsor, Doppel

    This episode is sponsored by Doppel, the AI-native social engineering defense platform. Doppel strengthens human risk management by training employees to recognize deception, while our digital risk protection detects and disrupts attacks across every channel. Learn more at doppel.com

    21 April 2026, 2:22 pm
  • 43 minutes 12 seconds
    Our Theoretical Controls Work Great Against Hypothetical Attacks

    Our Theoretical Controls Work Great Against Hypothetical Attacks

    All links and images can be found on CISO Series

    This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining is David Nolan, former CISO, Asurion.

    In this episode:

    • Influence, not control
    • The initiative gap
    • Skip the framework, patch the server
    • Confident code with no owner

    A huge thanks to our sponsor, ThreatLocker

    ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.

    14 April 2026, 10:00 am
  • 42 minutes 57 seconds
    Remember, Every Underappreciated Risk Is Just a Crisis Waiting to Be Discovered

    All links and images can be found on CISO Series.

    This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining us is Hilik Kotler, svp, CISO and IT, Expedia Group.

    In this episode:

    • The numbers game
    • What makes a vendor worth your time
    • Humanity in the loop
    • Alignment is a prerequisite, not a nice-to-have

    A huge thanks to our sponsor, Vanta

    Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

    7 April 2026, 10:00 am
  • 43 minutes 30 seconds
    Do You Think These Compliance Boxes Check Themselves? (LIVE in Clearwater, FL)

    All links and images can be found on CISO Series.

    This week's episode is hosted by David Spark, producer of CISO Series and Pam Lindemoen, CSO, vp of strategy, Retail and Hospitality-ISAC. Joining them is Jason Mayor, deputy CISO, Raymond James Financial.

    This episode was recorded in front of a live audience at the National Cybersecurity Alliance's Convene conference in Clearwater, Florida.

    In this episode:

    • Coaching security
    • Planned security theater
    • Making "nothing bad happened" a compelling story
    • Getting security teams to think like the business

    A huge thanks to our sponsor, Adaptive Security

    Sponsored by Adaptive Security – the first security awareness platform built to stop AI-powered social engineering. AI impersonation and deepfakes have made trust the new attack surface. Adaptive runs social-engineering simulations and instantly turns threats, policies, and compliance needs into interactive, multilingual training. Trusted by Fortune 500s. Learn more at adaptivesecurity.com.

    A huge thanks to our sponsor, Zepo

    Zepo Intelligence transforms employee behavior into measurable security capability. Moving beyond check-box compliance, our human risk management platform uses hyper-personalized simulations to turn your workforce into a proactive defense layer. We don't just improve human behavior; we enable mastery against modern social engineering threats. Learn more at zepo.ai.

    A huge thanks to our sponsor, KnowBe4

    KnowBe4 empowers workforces to make smarter security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage human risk. Our comprehensive AI-driven HRM+ platform includes modules for awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, and more. As the only global security platform of its kind, KnowBe4 utilizes personalized and relevant cybersecurity content, tools, and techniques to keep the modern workforce—both humans and AI agents—cybersafe from phishing, vishing, deepfakes, and all forms of social engineering. Learn more at knowbe4.com.

    31 March 2026, 10:00 am
  • 38 minutes 26 seconds
    Why Highlight Diversity When We Can Just Hope You Don't Notice?

    All links and images can be found on CISO Series.

    This week's episode is hosted by David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining is Julie Myerholtz, CISO, Brunswick Corporation.

    In this episode:

    • Your cloud, your problem
    • Kill your sacred cows
    • AI broke your vendor math
    • Feedback is a gift. Open it.

    A huge thanks to our sponsor, Vanta

    Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

    24 March 2026, 10:00 am
  • 41 minutes 54 seconds
    They're Less "Best Practices" and More "Sounds Good on LinkedIn"

    All links and images can be found on CISO Series.

    This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining us is Rebecca Harness, CISO, Deltek.

    In this episode:

    • Let it fail
    • The CIO seat is empty. Now what?
    • Design for how people actually work
    • "We found 23 issues. That'll be $15,000."

    Huge thanks to our sponsor, Strike48

    Strike48 is the Agentic Log Intelligence Platform that actually puts AI agents to work, combining full log visibility with AI agents that investigate, detect, and respond 24/7. With pre-built agent clusters for security and a no-code agentic workflow builder, it's easy to get started. Learn more at strike48.com/security.

    17 March 2026, 11:00 am
  • 48 minutes 29 seconds
    It's Okay to Put All Your Eggs in One Basket as Long as You Really Trust the Basket

    All links and images can be found on CISO Series.

    This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining us is our sponsored guest, Rob Allen, chief product officer, ThreatLocker.

    In this episode:

    • Your best employee is your biggest risk
    • Stop guessing the next attack
    • AI is not a feature
    • Stop blaming the user

    Huge thanks to our sponsor, ThreatLocker

    ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.

    10 March 2026, 11:00 am
  • 41 minutes 22 seconds
    Our Security Team's Love Language is Buying New Tools

    All links and images can be found on CISO Series.

    This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining us is our sponsored guest, Tim Leehealey, vp of corporate strategy and operations, Strike48.

    In this episode:

    • Defensible, not perfect
    • Tools aren't going to save you
    • Logs are wasted on the SOC
    • The myth of the lone wolf

    Huge thanks to our sponsor, Strike48

    Strike48 is the Agentic Log Intelligence Platform that actually puts AI agents to work, combining full log visibility with AI agents that investigate, detect, and respond 24/7. With pre-built agent clusters for security and a no-code agentic workflow builder, it's easy to get started. Learn more at strike48.com/security.

    3 March 2026, 11:00 am
  • 41 minutes 37 seconds
    If We Can't Do Better, at Least Do It Faster

    All links and images can be found on CISO Series.

    This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining them is Vikas Mahajan, vp and CISO, American Red Cross.

    In this episode:

    • Questionnaires aren't risk management
    • The good old days were worse
    • Buying or building your SOC
    • Start the conversation, not the checklist

    Huge thanks to our sponsor, Adaptive Security

    Sponsored by Adaptive Security—the first cybersecurity company backed by OpenAI. AI impersonation and deepfakes have made trust the new attack surface. Adaptive runs realistic social-engineering simulations and instantly turns threats, policies, and compliance needs into interactive, multilingual training. Trusted by Fortune 500s. Learn more at adaptivesecurity.com.

    24 February 2026, 11:00 am
  • 42 minutes 14 seconds
    We Gave the CISO Risk and Liability, and Now They Want Authority. The Nerve.

    All links and images can be found on CISO Series.

    This week's episode is hosted by David Spark, producer of CISO Series and Steve Zalewski. Joining them is Tammy Klotz, CISO, Trinseo.

    In this episode:

    • Accountability without authority
    • Kill your hacklore
    • Voice is no longer enough
    • Studies that tell us what we already know

    Huge thanks to our sponsor, ThreatLocker

    Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

    17 February 2026, 11:00 am
  • 42 minutes 32 seconds
    When We See White Smoke, We Know We Have a New CISO

    All links and images can be found on CISO Series.

    This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining them is Russ Ayres, CISO, Principal Financial Group.

    In this episode:

    • Metrics that matter
    • Tool babysitting problem
    • Automating the brokenness
    • Stay connected intentionally

    Huge thanks to our sponsor, Strike48

    Strike48 is the Agentic Log Intelligence Platform that actually puts AI agents to work, combining full log visibility with AI agents that investigate, detect, and respond 24/7. With pre-built agent clusters for security and a no-code agentic workflow builder, it's easy to get started. Learn more at strike48.com/security.

    10 February 2026, 11:00 am
  • More Episodes? Get the App