エピソード

  • The Player-Coach CISO: Engineering Trust in AI Agents with Open-Source Tools
    2026/08/27
    In this episode of The New CISO, host Steve Moore welcomes Sherri Douville for a conversation that sits outside the show's usual lane — less war story, more blueprint. Sherri works alongside CISOs rather than inside the role, and arrives with a pointed argument about what the job is becoming.She starts with why TTIC exists. IEEE UL 2933 gave healthcare a full-stack standard for clinical IoT device and data interoperability, but a standard on paper does nothing until it is adopted, implemented, and maintained. Getting there in a high-reliability industry means pulling in CIOs, CISOs, physicians, and engineers — and, Sherri admits, negotiating turf wars with bodies who assume you have come for their territory.Then the headline: how to make security cool. Sherri's answer starts with visibility — getting CISOs onto stages, onto podcasts, and into print in front of clinical leadership. Underneath it is a claim about trust. In healthcare, trust is the core of the business rather than an adjacent concern, which makes the CISO its natural steward. With AI pushing trust to the center of every industry, she argues that is the opening to become the rock star of the C-suite.Steve raises a banking CISO's framing of AI as a curious seven-year-old with a gun. Sherri pushes back on the spot: her analogy is the gifted teenager — capable, resource-hungry, and badly in need of direction. That leads to her real thesis. Scarce expertise used to carry economic value, and AI is rapidly compressing the worth of expert analysis. What appreciates instead is judgment, authority, execution, verification, organizational integration, and ownership of the outcome. Executives do not want more reports; they want the security problem to go away without adding coordination burden.The last stretch turns practical. Sherri walks through running Exabeam's open-source Praxen against Medigram's own code — painless to run, with remediation effort scaling to whatever standard you are chasing — and pairs it with Observra for continuous runtime telemetry. She closes on why it matters: when systems go down in a hospital, the real damage is not the outage hour but the fortnight of delays, miscommunications, and pile-up that follows for clinicians and patients.Key TopicsWhy standards bodies stall at adoption, not authorshipMaking security “cool”: visibility, stages, and executive presenceTrust as the core of the business in high-reliability industriesThe gifted teenager vs. the curious seven-year-old with a gunJudgment, authority, execution, verification, integration, ownershipSelective depth and the player-coach executiveRunning Praxen pre-deployment; Observra for runtime telemetryWhat a healthcare outage really costs, 14 to 20 days outGuest BioSherri Douville is CEO and Architect of Medigram and Founder and Chair of the Trustworthy Technology & Innovation Consortium (TTIC). She co-chairs the Trust subgroup of IEEE UL 2933 (TIPPSS), the standard for trust in clinical IoT. Medigram builds and operates Darwin, a governed AI decision platform whose agentic fleet runs in production and writes a sealed governance record at the moment of every agent action — an auditable trail for counsel, courts, insurers, and credit rating agencies. Sherri spent over a decade at Johnson & Johnson across a dozen disease states before physician leaders pulled her into healthcare IT and AI. She calls herself an accidental technologist: a domain expert who got into the code, logging 200 GitHub commits across June and July.GET A DEMO:👉 Get a hands-on demo of the Exabeam products: https://www.exabeam.com/demo🔔 Subscribe for more product demos and cybersecurity insights!ABOUT EXABEAM:Exabeam is the leader in Behavior Intelligence for the agentic enterprise. As organizations deploy digital workers and confront machine-speed adversaries, Exabeam applies agent-powered analytics to understand and govern the behavior of both human and non-human insiders. With integrated Exabeam Nova cybersecurity agents, Exabeam delivers flexible, industry-proven solutions for insider threat coverage of humans and agents and faster, more accurate threat detection, investigation, and response (TDIR). As the pioneer of user and entity behavior analytics (UEBA) and the innovator behind Agent Behavior Analytics (ABA), Exabeam is trusted by more than 3,000 enterprises worldwide to reduce risk, secure the digital workforce, and accelerate security operations. Learn more at www.exabeam.com.Exabeam: Stop Insider Threats. Human or AI.CONNECT WITH US:X: https://x.com/exabeamLinkedIn: https://www.linkedin.com/company/exabeam/Blog: https://www.exabeam.com/blog/
    続きを読む 一部表示
    49 分
  • Don’t Be a Risk Manager. Be a Trust Architect.
    2026/08/06

    Ravi Soin has clear advice for anyone starting a security career today: don't be a risk manager, be a trust architect. In this episode, Steve Moore sits down with Ravi—CIO and CISO at Smartsheet—for a builder's-eye conversation on the modern CISO role, AI as an accelerant on old sins, and why the CISO who still says “no” is already obsolete.

    Ravi traces his path through Sun Microsystems, RealNetworks, a decade at Microsoft, and 15 years at healthcare software leader Edifecs to his eight months at Smartsheet. He explains what it means to think about security the way builders do—understanding where corners get cut under sprint pressure—and why that inside-out perspective changes how you defend.

    Steve and Ravi dig into how Smartsheet is deploying agentic AI across the enterprise: a centralized knowledge graph tied to every corporate system, Claude-powered threat models, DAST and SAST scans, SOC triage on the 80% phishing baseline, and MCP-connected asset and license management.

    They name the old culture directly. It was an era of risk registers where lows and mediums were quietly punted, tens of thousands of known vulnerabilities were accepted as compensating- control fiction, and time-to-exploit was assumed to be forgiving. Both push back on the panicked reaction to the Mythos disclosures, arguing AI has simply closed the exploit window on the trash environments were already ignoring.

    Ravi's core advice: build trust into the system, think about security through the customer's lens, and treat AI agents as first-class identities under the same IAM principles you apply to humans. He and Steve close on how incident response must be re-fit for the agentic era, why auditability is the non-negotiable foundation of AI governance, and why community remains the sharpest source of learning.

    Key Topics

    • Thinking about security like a builder, from the inside out

    • Why the CISO who still says “no” is already obsolete

    • Deploying agentic AI across engineering, SOC, and corporate systems

    • MCP-connected asset and license management

    • The old risk-register culture and how the industry was gambling

    • Why the Mythos reaction missed the bigger story

    • Advice to your 21-year-old self: be a trust architect

    • Building security through the customer's lens

    Guest Bio

    Ravi Soin is the CIO and CISO at Smartsheet, where he leads global IT and security strategy for the AI-enhanced enterprise work management platform. He brings more than two decades of security and IT leadership, including 15 years as CIO and CISO at healthcare software leader Edifecs and product roles at Microsoft, RealNetworks, and Sun Microsystems. Ravi serves on the SeattleCIO advisory board and was named Seattle CIO of the Year.

    GET A DEMO:

    👉 Get a hands-on demo of the Exabeam products: https://www.exabeam.com/demo

    🔔 Subscribe for more product demos and cybersecurity insights!

    ABOUT EXABEAM:

    Exabeam is the leader in Behavior Intelligence for the agentic enterprise. As organizations deploy digital workers and confront machine-speed adversaries, Exabeam applies agent-powered analytics to understand and govern the behavior of both human and non-human insiders. With integrated Exabeam Nova cybersecurity agents, Exabeam delivers flexible, industry-proven solutions for insider threat coverage of humans and agents and faster, more accurate threat detection, investigation, and response (TDIR). As the pioneer of user and entity behavior analytics (UEBA) and the innovator behind Agent Behavior Analytics (ABA), Exabeam is trusted by more than 3,000 enterprises worldwide to reduce risk, secure the digital workforce, and accelerate security operations. Learn more at www.exabeam.com.

    Exabeam: Stop Insider Threats. Human or AI.

    CONNECT WITH US:

    X: https://x.com/exabeam

    LinkedIn: https://www.linkedin.com/company/exabeam/

    Blog: https://www.exabeam.com/blog/

    続きを読む 一部表示
    52 分
  • How Many Tokens to Breach Your Network?
    2026/07/16

    What if your next breach came down to a token budget? In this episode, Steve Moore is joined by Lou Rabon, Founder and CEO of Cyber Defense Group, for a conversation on the modern CISO's world—from how to interview for the seat, to why AI agents are the next insider threat, to research that reframes breach cost as a token calculation.

    Lou and Steve open on breach response, why making introductions during a crisis is a losing game, and the questions every CISO candidate should ask before accepting an offer. Lou lays out how many rounds of interviews a serious CISO role should include, why the CEO must be involved by the final round, and why he believes Legal—not the CIO or CTO—is the ideal reporting line for security.

    The conversation pivots to AI. Lou argues we are watching a dot-com-speed shift, only compressed. They dig into the emerging insider-threat framing for autonomous agents, the recent incident where an AI slipped its sandbox to contact a researcher, and why attackers face none of the ethical guardrails defenders must respect.

    Steve shares recent Cornell research showing that agentic tooling can already automate 22 of 32 steps in a corporate intrusion, compressing hours of expert work into seconds—with token spend as the only real limiter. If a breach can be priced in tokens, they argue, defenders must think in tokens too, and machine-to-machine defense becomes a necessity rather than a novelty.

    The episode closes on what Lou calls “the dirty secret” of cybersecurity: the unglamorous hygiene work—asset lists, data maps, MSA notification clocks—that no one wants to fund. He and Steve explore how agentic AI could finally deliver the always-on trash collection defenders have wanted for decades, from dynamic breach-notification tracking to a security agent that flags every new device.

    Key Topics

    • Why making introductions during a crisis is a losing strategy

    • The interview questions every CISO candidate should ask

    • Why Legal is the ideal reporting line for the CISO

    • The inverse curve between convenience and security

    • AI agents as the next form of insider threat

    • Cornell research: 22 of 32 intrusion steps automated

    • Tokens as the new unit of breach cost

    • Machine-to-machine defense in financial services

    • The “trash collection” hygiene work at the heart of InfoSec

    • Agentic AI for asset lists and breach-notification analysis

    Lou Rabon is the Founder and CEO of Cyber Defense Group (CDG), a cybersecurity strategic advisory firm he launched in 2016 to help fast-growing organizations manage modern risk and threats. With more than two decades in security, privacy, and incident response, Lou has led response engagements against nation-state attackers and previously served as CISO at Spokeo. Connect with Lou on LinkedIn or learn more at cdg.io.

    GET A DEMO:

    👉 Get a hands-on demo of the Exabeam products: https://www.exabeam.com/demo

    🔔 Subscribe for more product demos and cybersecurity insights!

    ABOUT EXABEAM:

    Exabeam is the leader in Behavior Intelligence for the agentic enterprise. As organizations deploy digital workers and confront machine-speed adversaries, Exabeam applies agent-powered analytics to understand and govern the behavior of both human and non-human insiders. With integrated Exabeam Nova cybersecurity agents, Exabeam delivers flexible, industry-proven solutions for insider threat coverage of humans and agents and faster, more accurate threat detection, investigation, and response (TDIR). As the pioneer of user and entity behavior analytics (UEBA) and the innovator behind Agent Behavior Analytics (ABA), Exabeam is trusted by more than 3,000 enterprises worldwide to reduce risk, secure the digital workforce, and accelerate security operations. Learn more at www.exabeam.com.

    Exabeam: Stop Insider Threats. Human or AI.

    CONNECT WITH US:

    X: https://x.com/exabeam

    LinkedIn: https://www.linkedin.com/company/exabeam/

    Blog: https://www.exabeam.com/blog/

    続きを読む 一部表示
    51 分
  • CISO 3.0: The Playbook for Delivering Impact and Influence
    2026/06/25

    What separates a CISO who survives from one who shapes the boardroom? In this episode, Steve Moore sits down with Walt Powell, Lead Field CISO at CDW and author of The CISO 3.0, to unpack the modern CISO playbook—why technical credentials alone no longer cut it, how to build personal eminence, and why most security leaders are still treated as second-class C-suite citizens.

    Walt traces his path from teaching networking before stateful firewalls existed, to writing CISSP exam questions for ISC2, to running CDW's Global Security Strategy Office. He explains what a field CISO does, why the role is harder than ex-CISOs realize, and how one bad meeting can tarnish a brand built over decades.

    He and Steve break down the four pillars Walt uses to measure his team—embedded advisory, eminence building, sales enablement, and voice of the customer—and how a karate-style “belt system” maps each consultant's competency. Walt explains why the same skills matrix from The CISO 3.0 works for any CISO trying to spot their own gaps.

    Walt argues a CISO who is not liked cannot succeed: you are the talent magnet, the culture builder, and the person proving in every board meeting that you belong in the seat. He shares the questions every candidate should ask before accepting the role—from D&O coverage to 10-K disclosure access—and why the 30-60-90 plan should be written before the second interview, not after the offer.

    The conversation closes with what Walt calls “strategic debt”—the identity and data governance work organizations skipped a decade ago that is now blocking AI adoption. Walt shares lessons from running OpenClaw on a Mac mini, why non-human identity tops every 2026 CISO worry list, and how Deep Research is reshaping senior architects.

    Key Topics

    • The modern field CISO role and the four pillars of impact

    • Why CISOs are still treated as second-class C-suite citizens

    • Building personal eminence through books, speaking, and writing

    • The CISO 3.0 skills matrix and self-assessment spider wheel

    • Two paths to the CISO seat: technical vs. MBA, and the gaps each leaves

    • Why likability is not optional for a successful CISO

    • Board readiness and proving you belong in the seat

    • Interview questions every CISO candidate must ask

    • Strategic debt: identity and data governance blocking AI adoption

    • OpenClaw, non-human identity, and the future of senior architects

    Guest Bio:

    Walt Powell is the Lead Field CISO at CDW and a founding member of CDW's Global Security Strategy Office, where he leads a team of former CISOs advising security leaders in the field. A longtime executive coach and ISC2 exam development committee member, Walt is the author of The CISO 3.0: A Guide to Next-Generation Cybersecurity Leadership and Quantum Ready, his book on post-quantum cryptography.

    Connect with Walt on LinkedIn or at ciso30.com.

    GET A DEMO:

    👉 Get a hands-on demo of the Exabeam products: https://www.exabeam.com/demo

    🔔 Subscribe for more product demos and cybersecurity insights!

    ABOUT EXABEAM:

    Exabeam is the leader in Behavior Intelligence for the agentic enterprise. As organizations deploy digital workers and confront machine-speed adversaries, Exabeam applies agent-powered analytics to understand and govern the behavior of both human and non-human insiders. With integrated Exabeam Nova cybersecurity agents, Exabeam delivers flexible, industry-proven solutions for insider threat coverage of humans and agents and faster, more accurate threat detection, investigation, and response (TDIR). As the pioneer of user and entity behavior analytics (UEBA) and the innovator behind Agent Behavior Analytics (ABA), Exabeam is trusted by more than 3,000 enterprises worldwide to reduce risk, secure the digital workforce, and accelerate security operations. Learn more at www.exabeam.com.

    Exabeam: Stop Insider Threats. Human or AI.

    CONNECT WITH US:

    X: https://x.com/exabeam

    LinkedIn: https://www.linkedin.com/company/exabeam/

    Blog: https://www.exabeam.com/blog/

    続きを読む 一部表示
    58 分
  • Rogue Agents: The New Era of AI Insider Threats (part 2)
    2026/06/04
    What happens when an AI agent inside your company starts behaving like an insider threat? In part two, Steve Moore picks the thread back up with former FBI operative Eric O'Neill to explore how agentic AI is rewriting cybersecurity, the legal traps that follow a breach, and why the modern CISO must think like a spy hunter.Eric opens with a sobering reality: ransomware victims who decline to pay are re-attacked at staggering rates. He explains why criminals treat cybercrime as a business, invest weeks in reconnaissance—mapping SharePoint, harvesting file trees, and studying access patterns—and why a botched recovery hands them the same door twice.The conversation turns to the new insider threat hiding in plain sight: rogue AI agents. Eric shares a real case in which one executive's casual query exposed the next round of layoffs and triggered coordinated lawsuits. They unpack how agents inherit excessive access, how attackers hijack them once inside, and why organizations are now building insider-threat programs to monitor AI behavior.Eric argues AI is an accelerant on every unresolved problem—weak identity management, entitlement drift, missing asset inventories, and absent data classification. They debate whether IT and security should be unified under the CISO, why the CISO needs a direct line to the board, and the legal landmines that follow a breach, from cyber insurance to the “reasonable steps” standard.The episode closes with Eric's advice for any new CISO: put “spy hunter” on your resume. Counterintelligence, not perimeter defense, is the discipline that wins today. Tune in for part two of a story-driven conversation on why preparation, mindset, and threat hunting beat any single technology.Key Topics• Why ransomware victims who decline to pay get re-attacked• How attackers map SharePoint, file trees, and access patterns• The new insider threat: rogue and hijacked AI agents• A real case of an AI agent exposing an HR layoff list• Shadow IT and the cost of banning AI outright• Permission structures and second-level reviews for agent actions• Why AI exposes gaps in identity, asset, and data classification• Unifying IT and security under the CISO• Why the CISO needs a direct line to the board• Legal traps: cyber insurance, reasonable steps, and missed alerts• The CISO as counterintelligence officer and spy hunterGuest BioEric O'Neill is a former FBI counterintelligence operative, attorney, and bestselling author who helped bring down Robert Hanssen—the most damaging spy in FBI history. He is the founder of NeXasure AI and co-founder of The Georgetown Group, and his undercover work was dramatized in the film Breach. Eric is the author of Gray Day and Spies, Lies, and Cybercrime.Connect with Eric on LinkedIn or at ericoneill.net.GET A DEMO:👉 Get a hands-on demo of the Exabeam products: https://www.exabeam.com/dem🔔 Subscribe for more product demos and cybersecurity insights!ABOUT EXABEAM:Exabeam is the leader in behavior intelligence for the agentic enterprise. As organizations deploy digital workers and confront machine-speed adversaries, Exabeam applies agent-powered analytics to understand and govern the behavior of both human and non-human insiders. With integrated Exabeam Nova cybersecurity agents, Exabeam delivers flexible, industry-proven solutions for insider threat coverage of humans and agents and faster, more accurate threat detection, investigation, and response (TDIR). As the pioneer of user and entity behavior analytics (UEBA) and the innovator behind Agent Behavior Analytics (ABA), Exabeam is trusted by more than 3,000 enterprises worldwide to reduce risk, secure the digital workforce, and accelerate security operations. Learn more at www.exabeam.com.Exabeam: Real Intelligence. Real Security. Real Fast.CONNECT WITH US:X: https://x.com/exabeamLinkedIn: https://www.linkedin.com/company/exabeam/Blog: https://www.exabeam.com/blog/
    続きを読む 一部表示
    43 分
  • Lessons From a Spy Hunter: The Real Cost of a Breach (Part 1)
    2026/05/14
    What does it feel like to stand in the smoking ruin of a ransomware attack? In this episode, Steve Moore is joined by former FBI undercover operative Eric O'Neill—the man who helped capture Robert Hanssen—to explain why modern cybercrime is just traditional espionage repackaged, and why the dark web has quietly become the world's third-largest economy.Eric traces his path from the FBI's counterintelligence trenches to founding NeXasure AI and writing cybersecurity books that read like spy thrillers. He and Steve unpack the staggering scale of cybercrime, which Eric predicts could reach $20 trillion in global GDP within years—a marketplace selling everything from ransomware kits to stolen credentials.They dismantle the “it won't happen to me” mindset that still lingers in boardrooms. Eric describes how attackers use AI agents to scan for vulnerable systems, walks through how Scattered Spider socially engineered MGM in a ten-minute phone call, and explains why disabled MFA remains the leading point of failure for small and mid-size businesses.Eric then unpacks the painful calculus of paying a ransom. He explains why the FBI says never pay, when OFAC sanctions make payment a federal crime, and why—even after paying—an organization must still do the same forensic, legal, and architectural work. Steve and Eric also detail how attackers resell access and treat victims as repeat customers. The episode closes with a candid look at recovery. Eric and Steve explore why most companies fail at restoration, why rolling back to “before the attack” leaves the original flaw wide open, and why preparation always beats panic. Tune in for a part-one masterclass for any leader who thinks their organization is too small to be a target.Key Topics• How traditional espionage evolved into modern cybercrime• The dark web as the world's third-largest economy• Why every organization is a target, regardless of size• The MGM ransomware attack and Scattered Spider's playbook• Disabled MFA as the leading cause of SMB compromise• Vulnerability assessments versus fire-time remediation costs• The pay-versus-don't-pay ransomware calculus• OFAC sanctions and the legal risks of paying• Why restoring backups is not the same as recovery• The how, where, why, what, and when of breach forensicsGuest BioEric O'Neill is a former FBI counterintelligence operative, attorney, and bestselling author who helped bring down Robert Hanssen—the most damaging spy in FBI history. He is the founder of NeXasure AI and co-founder of The Georgetown Group, and his undercover work was dramatized in the film Breach. Eric is the author of Gray Day and Spies, Lies, and Cybercrime.Connect with Eric on LinkedIn or at ericoneill.net.GET A DEMO:👉 Get a hands-on demo of the Exabeam products: https://www.exabeam.com/dem🔔 Subscribe for more product demos and cybersecurity insights!ABOUT EXABEAM:Exabeam is the leader in behavior intelligence for the agentic enterprise. As organizations deploy digital workers and confront machine-speed adversaries, Exabeam applies agent-powered analytics to understand and govern the behavior of both human and non-human insiders. With integrated Exabeam Nova cybersecurity agents, Exabeam delivers flexible, industry-proven solutions for insider threat coverage of humans and agents and faster, more accurate threat detection, investigation, and response (TDIR). As the pioneer of user and entity behavior analytics (UEBA) and the innovator behind Agent Behavior Analytics (ABA), Exabeam is trusted by more than 3,000 enterprises worldwide to reduce risk, secure the digital workforce, and accelerate security operations. Learn more at www.exabeam.com. Exabeam: Real Intelligence. Real Security. Real Fast.CONNECT WITH US:X: https://x.com/exabeamLinkedIn: https://www.linkedin.com/company/exabeam/Blog: https://www.exabeam.com/blog/
    続きを読む 一部表示
    35 分
  • Your Most Valuable Skills Aren’t Technical
    2026/04/23
    Cybersecurity debates tend to center on tools, frameworks, and threats. But Rob Knoblauch has built a 25-year career in global security leadership by focusing on the soft skills that determine whether a CISO survives, thrives, or burns out. In this episode of The New CISO, Rob joins Steve Moore to trace the through-line from running a multi-node BBS as a kid to serving as Deputy CISO of one of the world’s largest banks — and the career lessons he’s carried through every chapter.Rob’s path wasn’t engineered. It began with a VIC-20, a love of video games, and a side passion for DJing that eventually clinched his first big bank interview. Running a BBS taught him identity management, patching, and infrastructure long before those were industry terms, and responding to the Melissa and “I Love You” outbreaks as a twenty-something Toronto Stock Exchange analyst launched his pivot into information security.The conversation turns to leading at scale. Rob walks through the three mentors who shaped him — “the teacher” who grounded him in fundamentals at Bank of Montreal, “the coach” who taught him the collaborative nature of global operations at Scotiabank, and “the general” who sharpened his leadership edge. He frames these not as phases but as lenses he still applies situationally today.Rob and Steve dig into incident response — from taking down Canada’s first phishing site with no playbook to running tabletop exercises at the board, C-suite, and technical levels. Rob argues every organization needs a breach coach and that communications is the biggest make-or-break factor in a breach. He also offers a candid take on CISO politics — short tenures, CIO friction, and why trust with your boss matters more than being right.The episode closes with Rob’s take on why this may be the best time in history to be a new CISO. AI is stripping away the commodity work that defined earlier generations of the role, leaving more room for strategy, leadership, and real influence. For anyone stepping into the seat, Rob’s message is simple: the most valuable skills aren’t technical at all.Key Topics• Rob’s path from a VIC-20 and a grade-school BBS to the CISO seat• How DJing as “Robbie Knobs” clinched his first big bank interview — and why “notables” matter on a resume• Taking down the first phishing website in Canada with no playbook and a lot of cold calls• The three mentors who shaped his leadership: the teacher, the coach, and the general• Why tabletop exercises at the board, C-suite, and technical levels each matter — and how they differ• The case for engaging a breach coach before a breach happens, not during one• Why communications is the single biggest make-or-break factor in incident response• How AI is reshaping the CISO role by stripping away commodity workGuestRob Knoblauch — Chief Information Security OfficerRob Knoblauch is a seasoned CISO with 25+ years of global information security leadership. He began his career at the Toronto Stock Exchange during the Y2K era and later held increasingly senior roles at Bank of Montreal and Scotiabank, where he spent years as Deputy CISO and VP of Global Security Services. Rob is also a startup advisor and longtime house music DJ performing as “Robbie Knobs.” Connect with Rob on LinkedIn.GET A DEMO:👉 Get a hands-on demo of the Exabeam products: https://www.exabeam.com/demo🔔 Subscribe for more product demos and cybersecurity insights!ABOUT EXABEAM:Exabeam is the leader in behavior intelligence for the agentic enterprise. As organizations deploy digital workers and confront machine-speed adversaries, Exabeam applies agent-powered analytics to understand and govern the behavior of both human and non-human insiders. With integrated Exabeam Nova cybersecurity agents, Exabeam delivers flexible, industry-proven solutions for insider threat coverage of humans and agents and faster, more accurate threat detection, investigation, and response (TDIR). As the pioneer of user and entity behavior analytics (UEBA) and the innovator behind Agent Behavior Analytics (ABA), Exabeam is trusted by more than 3,000 enterprises worldwide to reduce risk, secure the digital workforce, and accelerate security operations. Learn more at www.exabeam.com.Exabeam: Real Intelligence. Real Security. Real Fast.CONNECT WITH US:X: https://x.com/exabeamLinkedIn: https://www.linkedin.com/company/exabeam/Blog: https://www.exabeam.com/blog/
    続きを読む 一部表示
    53 分
  • From Chef to CISO: Unlocking the Recipe to Security Leadership
    2026/04/02
    What does sharpening a knife over a case of onions have to do with incident response? For Myke Lyons, CISO at Cribl, the answer is everything. Myke trained at the Culinary Institute of America — learning speed and accuracy under the clock of a professional kitchen — before a summer IT job in Manhattan set him on an entirely different path. In this episode of The New CISO, host Steve Moore traces that journey and the surprising parallels between culinary craft and security leadership.The conversation moves through a career that evolved organically: a summer job moving refrigerator-sized printers in a Manhattan ad agency, a crash course in executive white-glove IT support, a breakthrough moment finally cracking subnetting, and a slow expansion from NOC operator to global security leader. Myke credits the kitchen — its insistence on precision and calm under fire — for instilling an operator's mindset that still defines how he leads through incidents today.Mentorship, both formal and accidental, threads through Myke's story. A curmudgeonly colleague who threatened to "replace him with a script" taught him the value of continuous improvement. A trusted mentor reframed the CISO's role with a single line about house fires and lock changes. And years in executive IT support gave Myke an early education in empathy and knowing when not to fix what wasn't asked.Myke and Steve examine a vendor incident where a product leader's dismissive response to a forensics question destroyed credibility with hundreds of customers. The lesson: saying "I don't know, but we'll find out" is not a weakness — it is the most powerful tool a leader has. The same insight applies to M&A due diligence, where reframing technical conversations as expectation-setting exercises turns adversarial interviews into collaborative ones.For Myke, the new CISO is defined by empathy and culture. Know your audience. Think like your customers. Communicate policy changes as explanations, not mandates. Find your internal advocates and invest in them before you need them. The recipe for great security leadership is less about technology than it is about people — and that lesson translates perfectly from the kitchen to the boardroom.Key Topics• Career pivots: from culinary school to IT and cybersecurity• Speed, accuracy, and craft — what kitchen discipline teaches security professionals• Building an operator's mindset and staying calm during security incidents• White-glove executive IT support and the patience, precision, and empathy it develops• Mentorship — formal and accidental — and the lessons that only land in retrospect• The dangers of filling silence with false confidence vs. the power of saying "I don't know"• Crisis communication best practices and what not to do during a vendor incident call• Managing M&A security due diligence with low-emotion, expectation-setting conversations• Building security culture through empathy, clear communication, and internal advocates• Telemetry, log management, and Cribl's role as the data engine for IT and security Guest BioMyke Lyons is the Chief Information Security Officer at Cribl, the AI platform for telemetry trusted by organizations worldwide — including half of the Fortune 100 — to manage IT and security data at any scale.He trained at the Culinary Institute of America with aspirations of becoming a food critic — until a summer IT job in Manhattan set him on an entirely different course. Myke went on to build expertise across networking, NOC operations, and log management, holding CISO positions at Snyk and Collibra before joining Cribl in 2024.Connect with Myke on LinkedIn and learn more about Cribl at cribl.io.GET A DEMO:👉 Get a hands-on demo of the Exabeam products: https://www.exabeam.com/demo🔔 Subscribe for more product demos and cybersecurity insights!ABOUT EXABEAM:Exabeam is the leader in behavior intelligence for the agentic enterprise. As organizations deploy digital workers and confront machine-speed adversaries, Exabeam applies agent-powered analytics to understand and govern the behavior of both human and non-human insiders. With integrated Exabeam Nova cybersecurity agents, Exabeam delivers flexible, industry-proven solutions for insider threat coverage of humans and agents and faster, more accurate threat detection, investigation, and response (TDIR). As the pioneer of user and entity behavior analytics (UEBA) and the innovator behind Agent Behavior Analytics (ABA), Exabeam is trusted by more than 3,000 enterprises worldwide to reduce risk, secure the digital workforce, and accelerate security operations. Learn more at www.exabeam.com. Exabeam: Real Intelligence. Real Security. Real Fast.CONNECT WITH US:X: https://x.com/exabeamLinkedIn: https://www.linkedin.com/company/exabeam/Blog: https://www.exabeam.com/blog/
    続きを読む 一部表示
    45 分