CISO Series Podcast

David Spark, Mike Johnson, and Andy Ellis

  • 37 minutes 47 seconds
    I'll Show You Our Resilience Plan Once Our Cloud Storage Is Back Online

    All links and images can be found on CISO Series.

    This week's episode is hosted by David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining them is Johann Balaguer, Global CISO, Hard Rock Hotels and Casinos.

    In this episode:

    • Understanding the why
    • Own your digital self
    • Invest beyond tenure
    • Prepare for dependencies

    Thanks to Louis Zhichao Zhang, AIA Australia for contributing this week's "What's Worse?!" scenario.

    Huge thanks to our sponsor, Guardsquare

    Guardsquare delivers mobile app security without compromise, providing advanced protections for both Android and iOS apps. From app security testing to code hardening to real-time visibility into the threat landscape, Guardsquare solutions provide enhanced mobile application security from early in the development process through publication. Learn more about how to protect your app at Guardsquare.com.

    27 January 2026, 11:00 am
  • 41 minutes 7 seconds
    AI Is Very Efficient at Making Us Forget the Value of Humans

    All links and images can be found on CISO Series.

    This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining them is Sara Madden, CISO, Convera.

    In this episode:

    • Hold developers accountable
    • Credibility through candor
    • Be strategic with AI deployment
    • Resources don't guarantee security

    Huge thanks to our sponsor, ThreatLocker

    ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.

    20 January 2026, 11:00 am
  • 40 minutes 37 seconds
    Managing Risk Has Been a Priority Ever Since You Asked About It (LIVE in NYC)

    All links and images can be found on CISO Series.

    This week's episode is hosted by David Spark, producer of CISO Series and Matthew Southworth, CSO, Priceline. Joining them is sponsored guest, Saket Modi, CEO, Safe Security. This episode was recorded live at FAIRCON25 in NYC.

    In this episode:

    • AI won't stay broken
    • Identity before intelligence
    • People decide risk appetite
    • Automate with oversight

    Huge thanks to our sponsor, Safe Security

    SAFE is the leader in Cyber Risk Quantification and the first company to deliver 100% autonomous Third-Party Risk Management. Powered by Agentic AI and built on FAIRtm, SAFE empowers CISOs, cybersecurity, and TPRM leaders to continuously quantify, prioritize, and mitigate cyber risks across their entire attack surface – enabling digital growth and organizational resilience. Learn more at testdrive.safe.security/

    13 January 2026, 11:00 am
  • 43 minutes 53 seconds
    Imagine Scaling Mistakes 5x Faster. Thank You, Automation! (LIVE in NY)

    All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark, producer of CISO Series and Matt Southworth, CISO, Priceline. Joining us is our sponsored guest, Leslie Nielsen, CISO, Mimecast.

    In this episode:

    • Automating dysfunction
    • Leading without dominating
    • Unglamorous wins
    • Code without comprehension

    Huge thanks to our sponsor, Mimecast.

    Cyber threats are getting smarter every day, and threat actors aren't just targeting your technology, they're targeting your most valuable asset - your people. Mimecast helps you identify and secure risk with a unified, intelligent platform that protects across the spectrum of threats; from email and chat to file sharing. Learn more at www.mimecast.com.

    6 January 2026, 11:00 am
  • 44 minutes 30 seconds
    How Much Risk Would a CISO Risk if a CISO Could Risk Risk? (LIVE in Boca Raton)

    All links and images can be found on CISO Series.

    This week's episode is hosted by David Spark, producer of CISO Series and Brett Conlon, CISO, American Century Investments. Joining them are Ryan Barras, CISO, Mount Sinai Medical Center.

    In this episode:

    • Nobody understands what we do
    • Someone else should fix this
    • Make the audience care
    • Speaking CEO

    Huge thanks to our sponsor, Dropzone AI

    Dropzone AI autonomously investigates every security alert—no playbooks needed. This AI SOC analyst queries your CrowdStrike, Splunk, threat intel feeds, and 60+ other tools to build complete investigations in 5 minutes. Unlike black-box automation, it shows every query, finding, and decision. See it work yourself—explore the self-guided demo at dropzone.ai.

    16 December 2025, 11:00 am
  • 39 minutes 56 seconds
    I'm Worried That We're Not Worried About the Right Worries With AI

    All links and images can be found on CISO Series.

    This week's episode is hosted by David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining them is their sponsored guest, Danny Jenkins, CEO, ThreatLocker.

    In this episode:

    • AI for AI's sake
    • Stop selling, start protecting
    • Stop calling everything sophisticated
    • Least privilege, rebranded

    Huge thanks to our sponsor, ThreatLocker

    ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.

    9 December 2025, 11:00 am
  • 35 minutes 8 seconds
    You Can't Fall Behind in AI if You Never Start

    All links and images can be found on CISO Series.

    This week's episode is hosted by me, David Spark, producer of CISO Series, and Mike Johnson, CISO, Rivian. Joining us is John Barrow, CISO, JB Poindexter & Co.

    In this episode:

    • Building unicorns, not hunting them
    • Cold War frameworks for modern threats
    • Trading dollars for stories
    • Mirror, mirror on the wall

    Huge thanks to our sponsor, Vanta

    Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information. A recent IDC analysis found that compliance teams using Vanta are 129% more productive. Get back time to focus on strengthening security and scaling your business at vanta.com/ciso

    2 December 2025, 11:00 am
  • 39 minutes 23 seconds
    Why Architect for Human Error When We Can Make People Feel Really Bad About It?

    All links and images can be found on CISO Series.

    This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis (@csoandy), principal of Duha. Joining them is Richard Rushing, CISO, Motorola Mobility.

    In this episode

    • Mindset over tools
    • When hygiene becomes risk
    • Systems for actual humans
    • Conversations over compliance

    Huge thanks to our sponsor, ThreatLocker

    ThreatLocker® Defense Against Configurations continuously scans endpoints to uncover misconfigurations, weak firewall rules, and risky settings that weaken defenses. With compliance mapping, daily updates, and actionable remediation in one dashboard, it streamlines hardening, reduces attack surfaces, and strengthens security. Learn more at threatlocker.com.
    25 November 2025, 11:00 am
  • 41 minutes 1 second
    Are You Implying This Line Graph Isn't a Compelling Cybersecurity Narrative?

    All links and images can be found on CISO Series.

    This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis (@csoandy), principal of Duha. Joining them is our sponsored guest, Nathan Hunstad, director, security, Vanta.

    In this episode:

    • Metrics that matter
    • Testing for real
    • AI as an assistant
    • Intelligence without context

    Huge thanks to our sponsor, Vanta

    Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information. A recent IDC analysis found that compliance teams using Vanta are 129% more productive. Get back time to focus on strengthening security and scaling your business at vanta.com/ciso

    18 November 2025, 11:00 am
  • 45 minutes 26 seconds
    Our CISO Certainly Puts the Tool in Multi-Tool (LIVE in LA)

    All links and images can be found on CISO Series.

    This week's episode is hosted by David Spark, producer of CISO Series and Jeff Steadman, deputy CISO, Corning Incorporated. Joining them is Quincey Collins, CSO, Sheppard Mullin. This episode was recorded live at the ISSA LA Summit in Santa Monica, California.

    In this episode:

    • The foundational debate
    • Strength over breadth
    • Beyond traditional backgrounds
    • Keeping perspective on risk

    Huge thanks to our sponsors, Adaptive Security and Dropzone AI

    AI-powered social engineering threats like deepfake voice calls, GenAI phishing, and vishing attacks are evolving fast. Adaptive helps security leaders get ahead with an AI-native platform that simulates realistic genAI attacks, and delivers expert-vetted security awareness training — all in one unified solution. Learn more at adaptivesecurity.com.

    Dropzone AI autonomously investigates every security alert—no playbooks needed. This AI SOC analyst queries your CrowdStrike, Splunk, threat intel feeds, and 60+ other tools to build complete investigations in 5 minutes. Unlike black-box automation, it shows every query, finding, and decision. See it work yourself—explore the self-guided demo at dropzone.ai.

    11 November 2025, 11:00 am
  • 39 minutes 26 seconds
    I Don't Just Guess About Effectiveness, I Make Educated Guesses!

    All links and images can be found on CISO Series.

    This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis (@csoandy), principal of Duha. Joining us is Sara Madden, CISO, Convera.

    In this episode:

    • Optimizing for reality, not idealism
    • Engineering governance instead of monitoring compliance
    • When AI finds what humans miss
    • The measurement problem

    Huge thanks to our sponsor, ThreatLocker

    Human error remains one of the top cybersecurity threats. Just one wrong click can open the door to ransomware or data loss. With ThreatLocker, unauthorized apps, scripts, and devices are blocked before they can ever run. See how ThreatLocker can help you gain more control over your environment. https://threatlocker.com
    4 November 2025, 10:00 am
  • More Episodes? Get the App