『Professor Simon's IT and Cybersecurity Podcast』のカバーアート

Professor Simon's IT and Cybersecurity Podcast

Professor Simon's IT and Cybersecurity Podcast

著者: Professor Simon
無料で聴く

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり
Welcome to The Professor Simon IT & Cybersecurity Podcast, where we go beyond the textbook with real-world career advice, practical guidance, and lessons from the field. Whether you're breaking into IT or cybersecurity, building your skills, transitioning careers, or planning your next move, you'll gain practical insights to help you make better career decisions and understand what the work actually looks like. Topics include careers, certifications, IT fundamentals, SOC, GRC, leadership, AI, cloud security, and more. Cyber & IT Beyond the Textbook.Professor Simon
エピソード
  • Cybersecurity Risk Management: What Makes a Decision Defensible?
    2026/10/08

    A year from now, somebody is going to look at a risk your organization chose to live with and ask why it was decided that way. Most of the time, they want to know whether anyone can explain it. In this episode, Professor Simon explains what makes a cybersecurity risk decision defensible: a decision that can be explained and supported using what was known at the time, whether or not it turned out well.

    He walks through a hypothetical, not a real case, about a business team that wants to connect a new tool to customer data before the security review is finished. Along the way, he covers seven things a good risk decision record should show and five questions it should be able to answer. It is useful for security and GRC professionals who make or document risk decisions, and for anyone learning to write them.

    In this episode you'll learn:

    - Why a defensible decision is one that can be explained using what was known at the time, not one that turned out well

    - Why cybersecurity risk decisions should be written down when they are made, not rebuilt from memory later

    - How to state a risk in plain words that a business decision maker can weigh

    - How to be honest about evidence, assumptions and confidence in a risk rating

    - Why a record should show the options considered, and keep security's recommendation separate from the decision

    - How to record residual risk, assumptions and constraints, and the triggers for reviewing a decision

    - Five questions a risk decision record should be able to answer


    ▶️ Companion YouTube Video: https://youtu.be/SzwZ2SGvL-U

    📝 Companion Blog Post: https://professorsimon.com/blog/defensible-cybersecurity-risk-decisions

    🎧 More Podcast Episodes: https://professorsimon.com/podcast

    👉 Need help with your IT or cybersecurity career? Work with me: https://professorsimon.com/guidance

    🔗 Resources, blog & more: https://professorsimon.com/links

    🌐 Website: https://professorsimon.com

    💼 LinkedIn: https://www.linkedin.com/in/leonardsimon

    📸 Instagram • X • TikTok: @profsimononline


    If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit.

    続きを読む 一部表示
    8 分
  • Who Decides During a Security Incident? | CISSP Blueprint
    2026/10/07

    When a security incident starts, who is actually allowed to decide to take a system offline, bring in legal, or tell the executives? In this CISSP Blueprint episode, Professor Simon looks at incident management through a security manager’s lens, using a fictional healthcare provider, IncidentSecure Inc., as a teaching scenario.

    He organizes the management side of the work into three questions: who decides, what is at stake, and what the organization will be able to show afterward. Along the way, he covers the difference between a role and the authority to decide, why severity should follow business impact, how legal, compliance, and communication planning fit in, and what evidence can show about an organization’s preparation and response. This is original teaching, not official ISC2 material, and it contains no exam questions.

    In this episode you'll learn:

    - Why incident management starts with authority and evidence, not tools

    - Where incident management sits in the published CISSP exam outline (Domain 7, Security Operations)

    - The difference between a role and the authority to decide, and why it matters during an incident

    - Why severity should follow business impact

    - Why legal, compliance, and communication planning belong in incident management

    - How an organization can demonstrate preparation and follow-through, including why drills need a record

    - Three questions to ask about any incident scenario, and what changes when you move toward security management


    ▶️ Companion YouTube Video: https://youtu.be/glg8OT8ei8w

    📝 Companion Blog Post: https://professorsimon.com/blog/who-decides-during-a-security-incident

    🎧 More Podcast Episodes: https://professorsimon.com/podcast

    👉 Need help with your IT or cybersecurity career? Work with me: https://professorsimon.com/guidance

    🔗 Resources, blog & more: https://professorsimon.com/links

    🌐 Website: https://professorsimon.com

    💼 LinkedIn: https://www.linkedin.com/in/leonardsimon

    📸 Instagram • X • TikTok: @profsimononline


    If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit.

    続きを読む 一部表示
    9 分
  • SOC vs GRC: Which Would You Actually Want to Do All Day?
    2026/10/06

    Choosing between SOC and GRC usually starts with salary, difficulty, or which one sounds more technical, and those comparisons rarely settle anything. A better question is which kind of work you would actually want to spend your time doing. In this episode, Professor Simon explains what SOC (security operations) work and GRC (governance, risk, and compliance) work tend to feel like day to day.

    He explains why the idea that SOC is technical and GRC is not does not hold up, walks through one illustrated vendor security problem from both seats, and covers where the two paths overlap. He then gives two small exercises you can try for free, one for each path, along with the questions to ask yourself afterward. Because this is audio, the exercises and questions are described as he goes, so you can follow along while you walk, drive or work.

    In this episode you'll learn:

    - Why salary, difficulty and 'which is better' are weak ways to choose between SOC and GRC

    - What SOC and GRC mean, and what each kind of work tends to involve day to day

    - Why 'SOC is technical and GRC is not' does not hold up

    - How the same vendor security problem raises different questions in a SOC and in GRC

    - What the two paths share: how systems work, clear writing, and separating what you know from what you assume

    - Two small free exercises to try the work before you pick a path

    - Questions to ask yourself afterward, and why being able to do the work is different from wanting to do it all day


    ▶️ Companion YouTube Video: https://youtu.be/7_Ww6uTrMws

    📝 Companion Blog Post:

    https://professorsimon.com/blog/soc-vs-grc-choose-based-on-the-work

    🎧 More Podcast Episodes: https://professorsimon.com/podcast

    🧭 Figure out which cybersecurity path fits you: https://careervectors.com

    🔗 Resources, blog & more: https://professorsimon.com/links

    🌐 Website: https://professorsimon.com

    💼 LinkedIn: https://www.linkedin.com/in/leonardsimon

    📸 Instagram • X • TikTok: @profsimononline


    If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit.

    続きを読む 一部表示
    9 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません