エピソード

  • #257 - Patch or Perish (with Ross Young)
    2025/11/03

    Imagine stepping into a role and discovering your predecessor had been severely underreporting vulnerabilities, leaving your systems 300 days behind on patches. Join G Mark Hardy and Ross Young in this riveting episode of CISO Tradecraft as they unveil a startling real-world scenario and a proven strategy to revolutionize your patching process. Learn how to tackle the ever-growing number of vulnerabilities, leverage AI and automation, and instill a culture of accountability and gamification among your team. With expert insights and practical steps, this episode is a must-watch for every cybersecurity leader looking to stay ahead of threats and secure their organization's future.

    Big thanks to our sponsor, Forcepoint. Check out how they can help you shut down ShadowAI. https://www.forcepoint.com/resources/ebooks/shadow-ai-security-guide?utm_source=linkedin&sf_src_cmpid=701a600000exxd7AAA&utm_medium=display&utm_content=AW_NC_LinkedInAds_October25_ban&utm_campaign=LinkedInAds_October25

    Note slides can be found here: https://www.linkedin.com/posts/mrrossyoung_patch-or-perish-activity-7389964440546471936--I_F?utm_source=share&utm_medium=member_desktop&rcm=ACoAABnnk5MBYbK8I-lYgI25f6ro7t6rOeP-Ods

    Chapters

    00:00 Introduction: The CISO Challenge 00:31 The Importance of Data Security 01:05 Welcome to CISO Tradecraft 02:01 Ross Young's Patching Journey 03:34 The Growing Threat of Vulnerabilities 05:16 AI and Cybersecurity 07:34 Developing a Comprehensive Security Approach 10:51 Accountability and Metrics 15:30 Improving Vulnerability Management Processes 19:28 Advanced Tooling and Automation 23:16 Future Trends in Cybersecurity 27:06 Conclusion: Adapting to the Future

    続きを読む 一部表示
    28 分
  • #256 - Maximize Your Cybersecurity Budgets (with Ross Young)
    2025/10/27

    In this episode of CISO Tradecraft, G Mark Hardy and Ross Young dive into part two of their series on cybersecurity budgets. Continuing from where they left off, they discuss the OWASP Threat and Safeguard Matrix (TaSM), effective protection scoring, and practical strategies to enhance your budget management as a CISO. Learn about the importance of understanding material threats, leveraging AI, and employing tools like murder boards to optimize security practices. Ross also shares inside tips for negotiating master service agreements and improving organizational processes, all aimed at making you a more effective security leader.

    続きを読む 一部表示
    44 分
  • #255 - Maximize the Outcomes Per Dollar in Cyber (with Ross Young)
    2025/10/20

    Welcome to another episode of CISO Tradecraft! Join G Mark Hardy and Ross Young as they dive deep into strategies for maximizing your security budget while minimizing waste. Ross, the author of the soon-to-be-released 'Cybersecurity's Dirty Secret,' shares insights from his 20-year career, including his time at the CIA, Capital One, and Caterpillar Financial. Get expert tips on zero-based budgeting, total cost of ownership, avoiding meeting waste, and more. Don't miss this episode if you want to learn how to make every cybersecurity dollar count!

    Free Templates: https://www.cisotradecraft.com/store

    Course: https://www.cisotradecraft.com/course-master-the-budget-game-in-cybersecurity

    続きを読む 一部表示
    45 分
  • #254 - AI, Privacy, & Security Insights (with Aimee Cardwell)
    2025/10/13

    Welcome to another insightful episode of CISO Tradecraft! In this episode, host G Mark Hardy engages with Aimee Cardwell, an accomplished cybersecurity expert with an impressive portfolio including UnitedHealth Group, AMEX, eBay, and more. Tune in as they dive deep into the increasing concerns of privacy, the evolving role of AI in cybersecurity, and the importance of data governance. Learn practical strategies for managing the complexities of AI and privacy, explore the intersections between cybersecurity and privacy, and get invaluable tips for aspiring CISOs. Don't miss this episode packed with expert advice and forward-thinking perspectives!

    Aimee Cardwell's Linkedin - https://www.linkedin.com/in/acardwell/

    続きを読む 一部表示
    37 分
  • #253 - DARPA’s AI Cyber Challenge Unveiled (with Andrew Carney)
    2025/10/06

    Dive into an exciting discussion on CISO Tradecraft as host G Mark Hardy engages with DARPA's AI Cyber Challenge director, Andrew Carney. Learn about the world of autonomous systems capable of identifying and fixing vulnerabilities at an unprecedented speed and scale. Discover the highs and lows of AIxCC's two-year journey, its groundbreaking impact on cybersecurity, and the potential it holds for the future. Whether you're a seasoned CISO or just passionate about cybersecurity, this episode is packed with insights on leveraging AI to protect critical infrastructure and defend against cyber threats. Don't miss it! https://aicyberchallenge.com/

    続きを読む 一部表示
    27 分
  • #252 - Master Storytelling for CISOs (with Neal Foard)
    2025/09/29

    Join us in this captivating episode of CISO Tradecraft as host G Mark Hardy sits down with storytelling maestro Neal Foard. Learn the secrets of impactful storytelling straight from Neal, who shares an engaging story about an unforgettable lesson at the New Jersey State Fair. Delve into the importance of emotions in storytelling, glean tips for effective communication, and discover how being an inspiring leader can propel your cybersecurity career. Don't miss this opportunity to enhance your storytelling prowess and become a more effective cybersecurity leader!

    続きを読む 一部表示
    1 時間 6 分
  • #251 - AI Just Changed Data Security Requirements (with Ronan Murphy)
    2025/09/22

    Learn how to elevate Data Protection in the Age of AI with Ronan Murphy In this episode of CISO Tradecraft, host G Mark Hardy and guest Ronan Murphy, Chief Strategy Officer at Forcepoint, discuss the critical importance of data protection for enterprises in the age of AI. Discover expert insights on common mistakes CISOs make, how AI revolutionizes data security, and the evolving role of CISOs from enforcers to strategists. Learn about effective data governance, AI’s impact on data, and leveraging tools like DLP & CASB for robust cybersecurity.

    Plus, hear about Forcepoint Aware 2025 and actionable strategies for elevating your organization's data security posture. https://www.forcepoint.com/aware

    続きを読む 一部表示
    44 分
  • #250 - Understanding Vulnerabilities, Exploits, and Cybersecurity
    2025/09/15

    Join host G Mark Hardy on CISO Tradecraft as he welcomes Patrick Garrity from VulnCheck and Tod Beardsley from Run Zero to discuss the latest in cybersecurity vulnerabilities, exploits, and defense strategies. Learn about their backgrounds, the complexities of security research, and strategies for effective communication within enterprises. The discussion delves into vulnerabilities, the significant risks posed by ransomware, and actionable steps for CISOs and security executives to protect their organizations. Stay tuned for invaluable insights on cybersecurity leadership and management.

    Chapters

    • 00:00 Introduction and Guest Welcome
    • 00:57 Meet Patrick Garrity: Security Researcher and Skateboard Enthusiast
    • 02:12 Meet Todd Beardsley: From Hacker to Security Research VP
    • 03:58 The Evolution of Vulnerabilities and Patching
    • 07:06 Understanding CVE Numbering and Exploitation
    • 14:01 The Role of Attribution in Cybersecurity
    • 16:48 Cyber Warfare and Global Threat Landscape
    • 20:18 The Rise of International Hacking
    • 22:01 Delegation of Duties in Offensive Warfare
    • 22:25 The Role of Companies in Cyber Defense
    • 23:00 Attack Vectors and Exploits
    • 24:25 Real-World Scenarios and Threats
    • 28:46 The Importance of Communication Skills for CISOs
    • 31:42 Ransomware: A Divisive Topic
    • 38:39 Actionable Steps for Security Executives
    続きを読む 一部表示
    47 分