Defense in Depth

David Spark

  • 30 minutes 18 seconds
    When You Just Can't Take It Anymore in Cyber

    All links and images for this episode can be found on CISO Series.

    Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Shawn Bowen, VP, Deputy CISO - Gaming, Microsoft. Joining us is Patty Ryan, senior director, CISO, QuidelOrtho.

    In this episode:

    • Recognizing humanity
    • Death by a thousand meetings
    • What are we looking for?
    • Find your value

    Thanks to our podcast sponsor, GitGuardian

    GitGuardian is a Code Security Platform that caters to the needs of the DevOps generation. It provides a wide range of code security solutions, including Secrets Detection, Infra as Code Security, and Honeytoken, all in one place. A leader in the market of secrets detection and remediation, its solutions are already used by hundreds of thousands of developers in all industries. Try now gitguardian.com.

    3 October 2024, 10:00 am
  • 37 minutes 13 seconds
    Is It Possible to Inject Integrity Into AI?

    All links and images for this episode can be found on CISO Series.

    Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Joining us is Davi Ottenheimer, vp, trust and digital ethics, Inrupt. Sir Tim Berners-Lee co-founded Inrupt to provide enterprise-grade software and services for the Solid Protocol. You can find their open positions here.

    In this episode:

    • LLMs lack integrity controls
    • A valid criticism
    • Doubts in self-policing AI
    • New tech, familiar problems

     Thanks to our podcast sponsor, Concentric AI

    Concentric AI’s DSPM solution automates data security, protecting sensitive data in real-time. Our AI-driven solution identifies, classifies, and secures on-premises and cloud data to reduce risk across your enterprise. Seamlessly integrated with tools like Microsoft Copilot, Concentric AI empowers your team to innovate securely and maintain compliance all while eliminating manual data protection tasks.

    Ready to put RegEx and trainable classifiers in the rear view mirror? Contact Concentric AI today!

    26 September 2024, 10:00 am
  • 27 minutes 36 seconds
    Are Phishing Tests Helping or Hurting Our Security Program?

    All links and images for this episode can be found on CISO Series.

    Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Joining us is Dennis Pickett, vp, CISO, Westat.

    In this episode:

    • Not all education requires tests
    • Understand your users
    • Building reflexes
    • An ounce of prevention

    Thanks to our podcast sponsor, Concentric AI

    Concentric AI’s DSPM solution automates data security, protecting sensitive data in real-time. Our AI-driven solution identifies, classifies, and secures on-premises and cloud data to reduce risk across your enterprise. Seamlessly integrated with tools like Microsoft Copilot, Concentric AI empowers your team to innovate securely and maintain compliance all while eliminating manual data protection tasks. 

    Ready to put RegEx and trainable classifiers in the rear view mirror? Contact Concentric AI today!

    19 September 2024, 10:00 am
  • 35 minutes 23 seconds
    ​​Who Is Responsible for Securing SaaS Tools?

    All links and images for this episode can be found on CISO Series.

    Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Russell Spitler, CEO and co-founder, Nudge Security.

    In this episode:

    • Defining responsibilities
    • Understanding the problem
    • A different role for security
    • Focus on the data

    Thanks to our podcast sponsor, Nudge Security

    Get a full inventory of all SaaS accounts ever created by anyone in your org, in minutes, along with automated workflows to scale SaaS security and governance. No agents, browser plug-ins or network changes required. Start today with a free 14-day trial.

    12 September 2024, 10:00 am
  • 29 minutes 47 seconds
    Hiring Cyber Teenagers with Criminal Records

    All links and images for this episode can be found on CISO Series.

    Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our guest, Adam Arellano, vp, enterprise cybersecurity, PayPal.

    In this episode:

    • Accounting for mindset
    • The importance of ethics
    • A matter of incentives
    • Understanding what is teachable

    Thanks to our podcast sponsor, ThreatLocker

    ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

    5 September 2024, 10:00 am
  • 31 minutes 2 seconds
    What's Working With Third-Party Risk Management?

    All links and images for this episode can be found on CISO Series.

    Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Nick Muy, CISO, Scrut Automation.

    In this episode:

    • Segment and test
    • Focus on you

    • Embrace the risk lifecycle

    • Not all vendors are the same

    Thanks to our podcast sponsor, Scrut Automation

    Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Our best-in-class features like process automation, AI, and 75+ native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit www.scrut.io to learn more or schedule a demo.

    29 August 2024, 10:00 am
  • 33 minutes 27 seconds
    What Triggers a CISO?

    All links and images for this episode can be found on CISO Series.

    Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Joining me is our guest, Sherron Burgess, CISO, BCD Travel.

    In this episode:

    • Disingenuous claims rub everyone the wrong way. 
    • Don’t put the CISO behind the 8-ball

    • The sales hustle

    • They didn’t understand the assignment

    Thanks to our podcast sponsor, Scrut Automation

    Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Our best-in-class features like process automation, AI, and 75+ native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit www.scrut.io to learn more or schedule a demo.

    22 August 2024, 10:00 am
  • 26 minutes 41 seconds
    Information Security vs. Cybersecurity

    All links and images for this episode can be found on CISO Series.

    Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and John Underwood, vp, information security, Big 5 Sporting Goods. Joining us is our guest, Mike Lockhart, CISO, EagleView.

    In this episode:

    • Marketing versus strategy
    • A distinction without a difference?
    • Terminology follows function
    • Security convergence 

    Thanks to our podcast sponsor, Scrut Automation

    Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Our best-in-class features like process automation, AI, and 75+ native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit www.scrut.io to learn more or schedule a demo.

    15 August 2024, 10:00 am
  • 30 minutes 8 seconds
    Should Deny By Default Be the Cornerstone of Zero Trust?

    All links and images for this episode can be found on CISO Series.

    Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Joining us is our sponsored guest Rob Allen, chief product officer, ThreatLocker.

    In this episode:

    • Can you retrofit zero trust?
    • The business case for deny by default
    • Seizing an opportunity
    • Zero trust doesn’t stand alone

    Thanks to our podcast sponsor, ThreatLocker

    ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

    8 August 2024, 10:00 am
  • 29 minutes 32 seconds
    What Is a Field CISO?

    All links and images for this episode can be found on CISO Series.

    Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Joining us is Bil Harmer, operating partner and CISO, Craft Ventures.

    In this episode:

    • A time and a place for Field CISOs
    • This isn’t a new role
    • Consulting the Field CISO
    • Words mean things

    Thanks to our podcast sponsor, Cyera

    Cyera’s AI-powered data security platform gives companies visibility over their sensitive data, context over the risk it represents, and actionable, prioritized remediation guidance.
 As a cloud-native, agentless platform, Cyera provides holistic data security coverage across SaaS, PaaS, IaaS and On-premise environments. Visit www.cyera.io to learn more.

    1 August 2024, 10:00 am
  • 30 minutes 35 seconds
    Cybersecurity Is a Communications Problem

    All links and images for this episode can be found on CISO Series.

    Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Geoff Belknap (@geoffbelknap). Joining us is Jim Bowie, CISO, Tampa General Hospital.

    In this episode:

    • The goal is to connect to the business
    • The hard truth about soft skills
    • Balancing risk
    • Looking beyond communication

    Thanks to our podcast sponsor, SeeMetrics

    SeeMetrics automates cybersecurity metrics programs, continuously measuring and helping prioritize risks based on context. SeeMetrics unifies siloed data from your security stack and offers hundreds of ready-to-use metrics. Once connected with SeeMetrics, security teams reduce risk, minimize exposure and optimize performance while eliminating tedious repetitive manual work.

    Ready to automate your security programs? start connecting your environment at seemetrics.co

    25 July 2024, 10:00 am
  • More Episodes? Get the App
© MoonFM 2024. All rights reserved.