エピソード

  • Cybercrime, Intelligence and Impact with Richard LaTulip
    2026/07/02

    Richard LaTulip joins Caffeinated Risk for a candid conversation connecting cybercrime investigations, threat intelligence, and practical business risk. Richard is a Field CISO with Recorded Future, a former United States Secret Service special agent, and both the author and real-life main character behind the true crime story Operation Carder Kaos.

    The discussion starts with Richard’s experience investigating organized cybercrime and quickly moves beyond the “kid in a hoodie” myth toward the reality of structured criminal ecosystems, specialized roles, and professionalized operations. From there, the conversation turns to what threat intelligence should actually do for security teams: be timely, relevant, and actionable.

    Tim, Doug, and Richard explore how organizations can use actionable intelligence to assess vulnerabilities based on actual business impact, not just severity scores or compliance checkboxes. That risk-based approach is a core ESRM touchstone and is becoming even more important as AI-assisted cyber attacks increase the speed, scale, and adaptability of adversaries.

    続きを読む 一部表示
    35 分
  • Risk Management - Enabling the pursuit of excellence with Joe Olivarez
    2026/05/07

    Visiting the Jacobs Engineering website you'll undoubtedly encounter the phrase "challenging today", an acknowledgement that the world is much more complex than ever before. While "it ain't like it used to be" can be said of any risk manager's portfolio, Joe Olivarez became the first global security leader in Jacobs history more than a dozen years ago. How much has changed in the last 3 years, let alone 13.
    Currently the Vice President, Operational Center of Excellence for Jacobs, Joe shares a candid discussion on how risk management has changed both wholistically as a profession and more specifically with large infrastructure projects. In addition to executive leadership for a world renowned organization, Mr. Olivarez is the most recent past president of ASIS , joining the show's own ASIS past president discussing ESRM roots.



    続きを読む 一部表示
    32 分
  • Risk conversations; Awkward, Unpopular and Essential - with Joshua Copeland
    2026/03/12

    Joshua Copeland's cyber security moniker is "The Unpopular Opinion Guy", while most of us in security roles have been that person with an unpopular opinion at least a time or two, Copeland turned it into both a book and a bit of a movement through numerous posts on Linkedin about many of the challenges in our industry.

    That said, this is not a mud slinging episode, Joshua had numerous, pragmatic examples of both the problem space and ways to address them. There are a lot of misconceptions about cyber security but there are also a wide array of real world impacts in our daily lives making this a very difficult area to master. Mr. Copeland has some of the unlock codes, making for another compelling episode.

    続きを読む 一部表示
    34 分
  • Cyber Security, the legal perspective with Brent Arnold
    2026/01/22

    "Legal and Regulatory" is a common receptor category in most enterprise risk matrices but with any luck most organizations have limited direct experience with cyber litigation matters. This episode jumps right into the deep end with one of Canada's preeminent cyber lawyers, Brent Arnold. Business law has evolved over hundreds of years, cybersecurity precedents began to appear on the legal landscape in the late 1980s and AI is the new kid on the block, barely out of diapers.

    While this episode can not be considered legal advice the chance to listen in on the ideas and opinions of from someone on the frontlines of this emerging risk vector should not be missed.

    続きを読む 一部表示
    34 分
  • Cyber Resilience, a National Solution with Herbert Fensury
    2025/12/04

    Cyber crime is now a daily fact of life and a significant concern in both the private and public sectors but our response capabilities do not seem to be keeping up. This episode dives deep into one organization that is combatting this problem with a combination of academic research, industry expertise and hands-on training with the founder and CEO, Herbert Fensury.

    While cyber security is a global problem, economics and politics dictate different solution requirements. The Canadian Cyber Assessment, Training and Experimentation (CATE) Centre is both cutting edge and focused on Canadian cyber resilience at both a regional and national level.

    続きを読む 一部表示
    30 分
  • Integrated Assurance with Patrick Hayes
    2025/10/23

    20 years after their paths first crossed, three Canadian security professionals regroup to discuss a new risk management strategy book based on hard won field experience. Patrick Hayes was a security strategist before organizations knew this was success differentiator. For decades he has been guiding organizations large and small, public, private and government on balancing business objectives with security. Mr. Haye's new book "Integrated Assurance: Unified Risk Strategy" is destined to become a reference for others tasked with supporting enterprise security and he has recently added a Substack series on the emerging threats of AI, again from the focus of an adversary intent on mission interruption.

    続きを読む 一部表示
    34 分
  • The Summer Show - 2025, (pt 2)
    2025/09/11

    Part 2 of this summer break episode takes a bit of a light hearted look at the cyber security industry predictions that become the norm in late December and early January. Eight or nine months later, how accurate where they? Take a listen, there are a couple surprises.

    The conversation uncovers a few ongoing challenges with the cyber security industry, from the digital divide associated with aging to organizational shifts away from engineering principles.

    A book by security pioneer Bruce Schneier is mentioned late in the show and Doug managed to mangle the title twice, but did read, and does recommend the book.

    続きを読む 一部表示
    28 分
  • The Summer Show - 2025, (pt 1)
    2025/08/28

    The summer show started with the light hearted goal of evaluating the top security predictions that fill the internet in late December each year. Forever unscripted, Tim and Doug wind up reflecting on the growing gap between physical and virtual information systems.

    While it is easy to lament, from a cognitive perspective there is little hope, the BSides movement, alive and well in Western Canada, is helping address that. It is almost inevitable that security and risk conversations involving society veer into AI, but get back on track with ESRM.

    Stay tuned for the predictions portion in part 2.

    続きを読む 一部表示
    26 分