『The New CISO』のカバーアート

The New CISO

The New CISO

著者: Steve Moore
無料で聴く

The New CISO is hosted by Exabeam Chief Security Strategist, Steve Moore. A former IT security leader himself, Steve sits down with Chief Information Security Officers to get their take on cybersecurity trends, what it takes to lead security teams and how things are changing in today’s world.517748 経済学
エピソード
  • The Player-Coach CISO: Engineering Trust in AI Agents with Open-Source Tools
    2026/08/27
    In this episode of The New CISO, host Steve Moore welcomes Sherri Douville for a conversation that sits outside the show's usual lane — less war story, more blueprint. Sherri works alongside CISOs rather than inside the role, and arrives with a pointed argument about what the job is becoming.She starts with why TTIC exists. IEEE UL 2933 gave healthcare a full-stack standard for clinical IoT device and data interoperability, but a standard on paper does nothing until it is adopted, implemented, and maintained. Getting there in a high-reliability industry means pulling in CIOs, CISOs, physicians, and engineers — and, Sherri admits, negotiating turf wars with bodies who assume you have come for their territory.Then the headline: how to make security cool. Sherri's answer starts with visibility — getting CISOs onto stages, onto podcasts, and into print in front of clinical leadership. Underneath it is a claim about trust. In healthcare, trust is the core of the business rather than an adjacent concern, which makes the CISO its natural steward. With AI pushing trust to the center of every industry, she argues that is the opening to become the rock star of the C-suite.Steve raises a banking CISO's framing of AI as a curious seven-year-old with a gun. Sherri pushes back on the spot: her analogy is the gifted teenager — capable, resource-hungry, and badly in need of direction. That leads to her real thesis. Scarce expertise used to carry economic value, and AI is rapidly compressing the worth of expert analysis. What appreciates instead is judgment, authority, execution, verification, organizational integration, and ownership of the outcome. Executives do not want more reports; they want the security problem to go away without adding coordination burden.The last stretch turns practical. Sherri walks through running Exabeam's open-source Praxen against Medigram's own code — painless to run, with remediation effort scaling to whatever standard you are chasing — and pairs it with Observra for continuous runtime telemetry. She closes on why it matters: when systems go down in a hospital, the real damage is not the outage hour but the fortnight of delays, miscommunications, and pile-up that follows for clinicians and patients.Key TopicsWhy standards bodies stall at adoption, not authorshipMaking security “cool”: visibility, stages, and executive presenceTrust as the core of the business in high-reliability industriesThe gifted teenager vs. the curious seven-year-old with a gunJudgment, authority, execution, verification, integration, ownershipSelective depth and the player-coach executiveRunning Praxen pre-deployment; Observra for runtime telemetryWhat a healthcare outage really costs, 14 to 20 days outGuest BioSherri Douville is CEO and Architect of Medigram and Founder and Chair of the Trustworthy Technology & Innovation Consortium (TTIC). She co-chairs the Trust subgroup of IEEE UL 2933 (TIPPSS), the standard for trust in clinical IoT. Medigram builds and operates Darwin, a governed AI decision platform whose agentic fleet runs in production and writes a sealed governance record at the moment of every agent action — an auditable trail for counsel, courts, insurers, and credit rating agencies. Sherri spent over a decade at Johnson & Johnson across a dozen disease states before physician leaders pulled her into healthcare IT and AI. She calls herself an accidental technologist: a domain expert who got into the code, logging 200 GitHub commits across June and July.GET A DEMO:👉 Get a hands-on demo of the Exabeam products: https://www.exabeam.com/demo🔔 Subscribe for more product demos and cybersecurity insights!ABOUT EXABEAM:Exabeam is the leader in Behavior Intelligence for the agentic enterprise. As organizations deploy digital workers and confront machine-speed adversaries, Exabeam applies agent-powered analytics to understand and govern the behavior of both human and non-human insiders. With integrated Exabeam Nova cybersecurity agents, Exabeam delivers flexible, industry-proven solutions for insider threat coverage of humans and agents and faster, more accurate threat detection, investigation, and response (TDIR). As the pioneer of user and entity behavior analytics (UEBA) and the innovator behind Agent Behavior Analytics (ABA), Exabeam is trusted by more than 3,000 enterprises worldwide to reduce risk, secure the digital workforce, and accelerate security operations. Learn more at www.exabeam.com.Exabeam: Stop Insider Threats. Human or AI.CONNECT WITH US:X: https://x.com/exabeamLinkedIn: https://www.linkedin.com/company/exabeam/Blog: https://www.exabeam.com/blog/
    続きを読む 一部表示
    49 分
  • Don’t Be a Risk Manager. Be a Trust Architect.
    2026/08/06

    Ravi Soin has clear advice for anyone starting a security career today: don't be a risk manager, be a trust architect. In this episode, Steve Moore sits down with Ravi—CIO and CISO at Smartsheet—for a builder's-eye conversation on the modern CISO role, AI as an accelerant on old sins, and why the CISO who still says “no” is already obsolete.

    Ravi traces his path through Sun Microsystems, RealNetworks, a decade at Microsoft, and 15 years at healthcare software leader Edifecs to his eight months at Smartsheet. He explains what it means to think about security the way builders do—understanding where corners get cut under sprint pressure—and why that inside-out perspective changes how you defend.

    Steve and Ravi dig into how Smartsheet is deploying agentic AI across the enterprise: a centralized knowledge graph tied to every corporate system, Claude-powered threat models, DAST and SAST scans, SOC triage on the 80% phishing baseline, and MCP-connected asset and license management.

    They name the old culture directly. It was an era of risk registers where lows and mediums were quietly punted, tens of thousands of known vulnerabilities were accepted as compensating- control fiction, and time-to-exploit was assumed to be forgiving. Both push back on the panicked reaction to the Mythos disclosures, arguing AI has simply closed the exploit window on the trash environments were already ignoring.

    Ravi's core advice: build trust into the system, think about security through the customer's lens, and treat AI agents as first-class identities under the same IAM principles you apply to humans. He and Steve close on how incident response must be re-fit for the agentic era, why auditability is the non-negotiable foundation of AI governance, and why community remains the sharpest source of learning.

    Key Topics

    • Thinking about security like a builder, from the inside out

    • Why the CISO who still says “no” is already obsolete

    • Deploying agentic AI across engineering, SOC, and corporate systems

    • MCP-connected asset and license management

    • The old risk-register culture and how the industry was gambling

    • Why the Mythos reaction missed the bigger story

    • Advice to your 21-year-old self: be a trust architect

    • Building security through the customer's lens

    Guest Bio

    Ravi Soin is the CIO and CISO at Smartsheet, where he leads global IT and security strategy for the AI-enhanced enterprise work management platform. He brings more than two decades of security and IT leadership, including 15 years as CIO and CISO at healthcare software leader Edifecs and product roles at Microsoft, RealNetworks, and Sun Microsystems. Ravi serves on the SeattleCIO advisory board and was named Seattle CIO of the Year.

    GET A DEMO:

    👉 Get a hands-on demo of the Exabeam products: https://www.exabeam.com/demo

    🔔 Subscribe for more product demos and cybersecurity insights!

    ABOUT EXABEAM:

    Exabeam is the leader in Behavior Intelligence for the agentic enterprise. As organizations deploy digital workers and confront machine-speed adversaries, Exabeam applies agent-powered analytics to understand and govern the behavior of both human and non-human insiders. With integrated Exabeam Nova cybersecurity agents, Exabeam delivers flexible, industry-proven solutions for insider threat coverage of humans and agents and faster, more accurate threat detection, investigation, and response (TDIR). As the pioneer of user and entity behavior analytics (UEBA) and the innovator behind Agent Behavior Analytics (ABA), Exabeam is trusted by more than 3,000 enterprises worldwide to reduce risk, secure the digital workforce, and accelerate security operations. Learn more at www.exabeam.com.

    Exabeam: Stop Insider Threats. Human or AI.

    CONNECT WITH US:

    X: https://x.com/exabeam

    LinkedIn: https://www.linkedin.com/company/exabeam/

    Blog: https://www.exabeam.com/blog/

    続きを読む 一部表示
    52 分
  • How Many Tokens to Breach Your Network?
    2026/07/16

    What if your next breach came down to a token budget? In this episode, Steve Moore is joined by Lou Rabon, Founder and CEO of Cyber Defense Group, for a conversation on the modern CISO's world—from how to interview for the seat, to why AI agents are the next insider threat, to research that reframes breach cost as a token calculation.

    Lou and Steve open on breach response, why making introductions during a crisis is a losing game, and the questions every CISO candidate should ask before accepting an offer. Lou lays out how many rounds of interviews a serious CISO role should include, why the CEO must be involved by the final round, and why he believes Legal—not the CIO or CTO—is the ideal reporting line for security.

    The conversation pivots to AI. Lou argues we are watching a dot-com-speed shift, only compressed. They dig into the emerging insider-threat framing for autonomous agents, the recent incident where an AI slipped its sandbox to contact a researcher, and why attackers face none of the ethical guardrails defenders must respect.

    Steve shares recent Cornell research showing that agentic tooling can already automate 22 of 32 steps in a corporate intrusion, compressing hours of expert work into seconds—with token spend as the only real limiter. If a breach can be priced in tokens, they argue, defenders must think in tokens too, and machine-to-machine defense becomes a necessity rather than a novelty.

    The episode closes on what Lou calls “the dirty secret” of cybersecurity: the unglamorous hygiene work—asset lists, data maps, MSA notification clocks—that no one wants to fund. He and Steve explore how agentic AI could finally deliver the always-on trash collection defenders have wanted for decades, from dynamic breach-notification tracking to a security agent that flags every new device.

    Key Topics

    • Why making introductions during a crisis is a losing strategy

    • The interview questions every CISO candidate should ask

    • Why Legal is the ideal reporting line for the CISO

    • The inverse curve between convenience and security

    • AI agents as the next form of insider threat

    • Cornell research: 22 of 32 intrusion steps automated

    • Tokens as the new unit of breach cost

    • Machine-to-machine defense in financial services

    • The “trash collection” hygiene work at the heart of InfoSec

    • Agentic AI for asset lists and breach-notification analysis

    Lou Rabon is the Founder and CEO of Cyber Defense Group (CDG), a cybersecurity strategic advisory firm he launched in 2016 to help fast-growing organizations manage modern risk and threats. With more than two decades in security, privacy, and incident response, Lou has led response engagements against nation-state attackers and previously served as CISO at Spokeo. Connect with Lou on LinkedIn or learn more at cdg.io.

    GET A DEMO:

    👉 Get a hands-on demo of the Exabeam products: https://www.exabeam.com/demo

    🔔 Subscribe for more product demos and cybersecurity insights!

    ABOUT EXABEAM:

    Exabeam is the leader in Behavior Intelligence for the agentic enterprise. As organizations deploy digital workers and confront machine-speed adversaries, Exabeam applies agent-powered analytics to understand and govern the behavior of both human and non-human insiders. With integrated Exabeam Nova cybersecurity agents, Exabeam delivers flexible, industry-proven solutions for insider threat coverage of humans and agents and faster, more accurate threat detection, investigation, and response (TDIR). As the pioneer of user and entity behavior analytics (UEBA) and the innovator behind Agent Behavior Analytics (ABA), Exabeam is trusted by more than 3,000 enterprises worldwide to reduce risk, secure the digital workforce, and accelerate security operations. Learn more at www.exabeam.com.

    Exabeam: Stop Insider Threats. Human or AI.

    CONNECT WITH US:

    X: https://x.com/exabeam

    LinkedIn: https://www.linkedin.com/company/exabeam/

    Blog: https://www.exabeam.com/blog/

    続きを読む 一部表示
    51 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません