- 37 minutes 52 secondsOur Data Security Policy Is Transparent in That It Doesn't Exist
Our Data Security Policy Is Transparent in That It Doesn't Exist
All links and images can be found on CISO Series
This week's episode is hosted by David Spark, producer of CISO Series, and Mike Johnson, CISO, Rivian. Joining is Mike Melo, CISO, TMX Group.
In this episode:
- The weight of old controls
- Data you can actually see
- 68 vendors and counting
- Authority you never had to claim
A huge thanks to our sponsor, Vanta
Still stuck on the quarterly audit treadmill? Meet Calm-pliance. Vanta combines compliance, risk, and proof on one Agentic Trust Platform—and continuously monitors your controls, keeping you audit-ready all year round. Find your Calm-pliance here.
2 June 2026, 10:00 am - 40 minutes 10 secondsIf You Love Cloud Misconfigurations So Much, Why Don't You Marry Them!
All links and images can be found on CISO Series
This week's episode is hosted by David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining them is their sponsored guest Amit Megiddo, CEO and founder, Native.
In this episode:
- The CISO you don't need
- Misconfigurations aren't a cloud problem
- Secure by design means enforcing it
- Finding bugs faster isn't the bottleneck
A huge thanks to our sponsor, Native
Native makes secure-by-design inherent to how the cloud operates. It's the control plane for built-in cloud security, unifying and governing native controls, so security intent is defined once and applied consistently across providers. Learn more at native.security.
26 May 2026, 10:00 am - 41 minutes 35 secondsWhy Be Responsible When We Can Just Blame AI?
All links and images can be found on CISO Series
This week's CISO Series Podcast features David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining us is our sponsored guest, Jadee Hanson, CISO, Vanta.
In this episode:
- The compliance receipt nobody reads
- Who signs off on the AI that wrote the code
- The agent that wouldn't stop
- The questionnaire that should not exist
A huge thanks to our sponsor, Vanta
Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
19 May 2026, 10:00 am - 36 minutes 49 secondsCan You Please Train the AI on Your Way Out the Door?
All links and images can be found on CISO Series
This week's episode is hosted by David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining is Jean-Paul Calabio, vp and CISO, Grainger.
In this episode:
- Scanning the map isn't securing the territory
- CFOs don't fund faith
- What your AI inherits
- Nobody owns the gap
Thanks to Jonathan Waldrop, CISO, Acoustic for providing our "What's Worse" scenario.
A huge thanks to our sponsor, ThreatLocker
ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.
12 May 2026, 10:00 am - 43 minutes 28 secondsAI Confidence: It's a Trap! (LIVE in San Francisco)
All links and images can be found on CISO Series
This week's episode is hosted by David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining is Sara Madden, CISO, Convera. This episode was recorded live at BSidesSF 2026.
In this episode:
- Playing vendor roulette
- Confident and wrong
- Making conferences count
- The stakes problem in tabletops
A huge thanks to our sponsor, QuilrAI
Can you tell if an action in your environment was performed by a human — or an AI agent? QuilrAI's Decision Engine evaluates content, context, and intent before actions complete — across browsers, endpoints, SaaS, LLMs, and agents. Not more alerts. Better decisions, in real time. Visit quilr.ai.
A huge thanks to our sponsor, Nudge Security
Get a full inventory of AI assets on Day One of your free trial, even those introduced before you started using Nudge. Get started.
A huge thanks to our sponsor, Zenity
Help shape the future of AI agent security. On May 27th, the AI Agent Security Summit returns to San Francisco. Hear from leading researchers and security pioneers, and usher in the new age of secure AI deployment across the enterprise. Register at zenity.io/ai-security-summit.
5 May 2026, 10:00 am - 42 minutes 40 secondsStep 1: Deploy New AI Tool. Step 2: Discover Security Flaws. Step 3: Repeat. (LIVE in Orlando)
All links and images can be found on CISO Series
This week's episode is hosted by David Spark, producer of CISO Series and Michelle Wilson, CISO, Movement Mortgage. Joining is sponsored guest Rob Allen, chief product officer, ThreatLocker.
This show was recorded in front of a live audience at ThreatLocker's conference, Zero Trust World 2026.
In this episode:
- Risk as a daily habit
- AI agents talking to AI agents
- The code on the lock
- Words that shape decisions
A huge thanks to our sponsor, ThreatLocker
ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.
28 April 2026, 10:00 am - 39 minutes 59 secondsBack in My Day, You Could Get a Cybersecurity Job at the Corner Store
All links and images can be found on CISO Series
This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining is Paul Drapeau, head of global information security, New Balance.
In this episode:
- The logo trap
- Immunity through exposure
- The synthesis edge
- The cost of holding tight
A huge thanks to our sponsor, Doppel
This episode is sponsored by Doppel, the AI-native social engineering defense platform. Doppel strengthens human risk management by training employees to recognize deception, while our digital risk protection detects and disrupts attacks across every channel. Learn more at doppel.com
21 April 2026, 2:22 pm - 43 minutes 12 secondsOur Theoretical Controls Work Great Against Hypothetical Attacks
Our Theoretical Controls Work Great Against Hypothetical Attacks
All links and images can be found on CISO Series
This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining is David Nolan, former CISO, Asurion.
In this episode:
- Influence, not control
- The initiative gap
- Skip the framework, patch the server
- Confident code with no owner
A huge thanks to our sponsor, ThreatLocker
ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.
14 April 2026, 10:00 am - 42 minutes 57 secondsRemember, Every Underappreciated Risk Is Just a Crisis Waiting to Be Discovered
All links and images can be found on CISO Series.
This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining us is Hilik Kotler, svp, CISO and IT, Expedia Group.
In this episode:
- The numbers game
- What makes a vendor worth your time
- Humanity in the loop
- Alignment is a prerequisite, not a nice-to-have
A huge thanks to our sponsor, Vanta
Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
7 April 2026, 10:00 am - 43 minutes 30 secondsDo You Think These Compliance Boxes Check Themselves? (LIVE in Clearwater, FL)
All links and images can be found on CISO Series.
This week's episode is hosted by David Spark, producer of CISO Series and Pam Lindemoen, CSO, vp of strategy, Retail and Hospitality-ISAC. Joining them is Jason Mayor, deputy CISO, Raymond James Financial.
This episode was recorded in front of a live audience at the National Cybersecurity Alliance's Convene conference in Clearwater, Florida.
In this episode:
- Coaching security
- Planned security theater
- Making "nothing bad happened" a compelling story
- Getting security teams to think like the business
A huge thanks to our sponsor, Adaptive Security
Sponsored by Adaptive Security – the first security awareness platform built to stop AI-powered social engineering. AI impersonation and deepfakes have made trust the new attack surface. Adaptive runs social-engineering simulations and instantly turns threats, policies, and compliance needs into interactive, multilingual training. Trusted by Fortune 500s. Learn more at adaptivesecurity.com.
A huge thanks to our sponsor, Zepo
Zepo Intelligence transforms employee behavior into measurable security capability. Moving beyond check-box compliance, our human risk management platform uses hyper-personalized simulations to turn your workforce into a proactive defense layer. We don't just improve human behavior; we enable mastery against modern social engineering threats. Learn more at zepo.ai.
A huge thanks to our sponsor, KnowBe4
KnowBe4 empowers workforces to make smarter security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage human risk. Our comprehensive AI-driven HRM+ platform includes modules for awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, and more. As the only global security platform of its kind, KnowBe4 utilizes personalized and relevant cybersecurity content, tools, and techniques to keep the modern workforce—both humans and AI agents—cybersafe from phishing, vishing, deepfakes, and all forms of social engineering. Learn more at knowbe4.com.
31 March 2026, 10:00 am - 38 minutes 26 secondsWhy Highlight Diversity When We Can Just Hope You Don't Notice?
All links and images can be found on CISO Series.
This week's episode is hosted by David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining is Julie Myerholtz, CISO, Brunswick Corporation.
In this episode:
- Your cloud, your problem
- Kill your sacred cows
- AI broke your vendor math
- Feedback is a gift. Open it.
A huge thanks to our sponsor, Vanta
Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
24 March 2026, 10:00 am - More Episodes? Get the App