エピソード

  • We All Agree That Prevention Is the Best Advice We're Never Going to Follow
    2025/09/09

    All links and images can be found on CISO Series.

    This week’s episode is hosted by David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining us is Jason Loomis, CISO, Freshworks.

    In this episode:

    • Making organizations take their security medicine
    • Building CISO support systems
    • Holding the door for humans
    • Underappreciated risks: beyond the headlines

    Huge thanks to our sponsor, Safe Security

    SAFE is the category leader in Cyber Risk Quantification (CRQ) and the first vendor to deliver fully autonomous Third-Party Risk Management.We help CISOs, GRC, and TPRM leaders continuously and efficiently quantify, prioritize, and mitigate cyber risks across their entire attack surface — enabling digital growth and resilience. Learn more at tprmdemo.safe.security.

    続きを読む 一部表示
    44 分
  • We're All for a Responsible AI Rollout as Long as It Goes as Fast as Possible
    2025/09/02

    All links and images can be found on CISO Series.

    This week’s episode is hosted by David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining them is Jennifer Swann, CISO, Bloomberg Industry Group.

    In this episode:

    • Vulnerability management vs. configuration control
    • Open source security and supply chain trust
    • Building security leadership presence
    • AI governance and enterprise risk

    Huge thanks to our sponsor, Vanta

    Vanta’s Trust Management Platform automates key areas of your GRC program—including compliance, internal and third-party risk, and customer trust—and streamlines the way you gather and manage information. A recent IDC analysis found that compliance teams using Vanta are 129% more productive. Get started today at Vanta.com/CISO.

    続きを読む 一部表示
    40 分
  • New Study Finds No Email Has Ever “Found You Well”
    2025/08/26

    All links and images can be found on CISO Series.

    This week’s episode is hosted by me, David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is David Cross, CISO, Atlassian.

    In this episode:

    • Breaking the Sales Cycle
    • Leadership Under Fire
    • Predicting the Unpredictable
    • Security Startups' Security Paradox

    A huge thanks to our sponsor, ThreatLocker

    ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

    続きを読む 一部表示
    34 分
  • I Just Can’t Communicate With the Business. I’ve Tried Condescension AND Derision.
    2025/08/19

    All links and images can be found on CISO Series.

    This week’s episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis (@csoandy), principal of Duha. Joining us is Gary Chan, CISO, SSM Health. Be sure to check out Gary's security mentalism website: https://www.gschan2000.com.

    In this episode:

    • Decision-making with incomplete information
    • Translation beats technical expertise
    • Influence trumps authority for CISOs
    • Technical prowess creates adversaries

    Huge thanks to our sponsor, Vanta

    Automate, centralize, & scale your GRC program with Vanta. Vanta’s Trust Management Platform automates key areas of your GRC program—including compliance, internal and third-party risk, and customer trust—and streamlines the way you gather and manage information. And the impact is real: A recent IDC analysis found that compliance teams using Vanta are 129% more productive. Get started at Vanta.com/ciso.
    続きを読む 一部表示
    36 分
  • Impressive! Our AI is Approaching “One 9” of Accuracy.
    2025/08/12

    All links and images can be found on CISO Series.

    This week’s episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis (@csoandy), principal of Duha. Joining us is our sponsored guest, Kevin Tian, co-founder and CEO, Doppel.

    In this episode:

    • AI fraud gets on the juice
    • Agentic AI demands a new security mindset
    • The new frontier for social engineering
    • We still need human verification

    Huge thanks to our sponsor, Doppel

    Doppel is the first social engineering defense platform built to dismantle deception at the source. It uses AI and infrastructure correlation to detect, link, and disrupt impersonation campaigns before they spread - protecting brands, executives, and employees while turning every threat into action that strengthens defenses across a shared intelligence network.

    続きを読む 一部表示
    40 分
  • They Can’t Hack All Our Tools If We Keep Buying New Ones
    2025/08/05

    All links and images can be found on CISO Series.

    This week’s episode is hosted by me, David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining them is their sponsored guest, Rajan Kapoor, CEO of Material Security.

    In this episode:

    • AI creates security's catch-22
    • Delegation without abandonment
    • Google's security gaps demand better tools
    • Trust beats sophistication every time

    A huge thanks to our sponsor, Material Security

    What if you could get a view of security across Google Workspace–email, documents, and accounts–all in one place? Material Security unifies your Google Workspace security operations, simplifying and strengthening security with continuous monitoring and automatic issue resolution. See how Material Security simplifies your security for GMail, GDrive and Google accounts. Learn more at https://material.security.

    続きを読む 一部表示
    34 分
  • Cosmo Quiz! 23 Ways to Make Your Vendors Obsessed With Your Security Standards
    2025/07/29

    All links and images can be found on CISO Series.

    This week’s episode is hosted by me, David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is our sponsored guest, Rob Allen, chief product officer, ThreatLocker.

    In this episode:

    • Large enterprise security demands drive vendor improvements
    • Technical expertise becomes leadership liability without delegation
    • EDR evolution needs prevention focus
    • Career breaks require personal ownership and strategic timing

    A huge thanks to our sponsor, ThreatLocker

    ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

    続きを読む 一部表示
    39 分
  • We’ll Worry About Recovering From the Attack Once We Ace This Audit
    2025/07/22

    All links and images can be found on CISO Series.

    This week’s episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis (@csoandy), partner, YL Ventures. Joining us is Peter Clay, CISO, Aireon.

    In this episode:

    • Purple teaming evolution misses operational realities
    • Effective postmortems require systematic failure analysis
    • Risk expertise requires business context over methodology
    • Compliance and resilience serve different purposes

    Huge thanks to our sponsor, Safe Security

    SAFE is reinventing Third-Party Risk Management with Agentic AI. Our AI Agents automate onboarding, assessments, and monitoring—giving security teams real-time visibility and zero-effort control across their vendor ecosystem. See why SAFE is the fastest-growing TPRM platform on the market at https://testdrive.safe.security/.

    続きを読む 一部表示
    43 分