エピソード

  • Episode 49: Show Me What Risk You're Buying Down
    2026/09/16

    Most CISOs cannot draw a line from what they spend to the risk it reduces. Jake Bernardes, CISO, thinks that is the core failure of the role.

    In this episode of Zero Trust Journey, Jake lays out how he triages a security program: what is actually on fire, what is blocking the business from selling, and what risk every dollar is buying down. Everything else is noise.

    🔹 The chartered accountant who became a pen tester who became a CISO
    🔹 Why financial literacy is the skill most security leaders are missing
    🔹 Every tool, service, and headcount: show me the risk it buys down
    🔹 The AI and GRC question nobody answers honestly: is internal audit going away?
    🔹 The tuning tax, the hours you spend teaching AI to do the job
    🔹 Zero to FedRAMP Moderate in six months, with almost no budget and almost no team
    🔹 Day one advice for a first-time CISO walking into zero program

    Subscribe to our LinkedIn to never miss news, updates, and quizzes to earn digital badges.

    • https://ztjourney.com
    • LinkedIn
    • YouTube

    Disclaimer: The views expressed are those of the speakers.

    続きを読む 一部表示
    15 分
  • Episode 48: The Wireless Blind Spot in Your Zero Trust Architecture
    2026/06/28

    62% of security teams have no idea what's happening in their wireless environment. Is yours one of them?

    In this episode of the Zero Trust Journey Podcast, host Victor Monga sits down with wireless security expert Brett Walkenhorst to tackle the most overlooked attack surface in enterprise security — wireless. While most Zero Trust conversations orbit around identity, cloud, and network, wireless quietly remains the forgotten frontier. And attackers know it.
    Brett breaks down why Wi-Fi is just the tip of the iceberg, how continuous monitoring beats annual audits, and why wireless-related CVEs are growing 20x faster than the overall CVE rate — a stat that should stop every security architect in their tracks.

    🔑 Key Topics Covered:

    • Why wireless goes far beyond Wi-Fi — Bluetooth, Zigbee, cellular, and IoT all count
    • How Software-Defined Radios (SDR) enable spectrum-wide protocol discovery
    • The TSCM model and why point-in-time sweeps simply aren't enough
    • Continuous monitoring as the wireless equivalent of always-on packet inspection
    • Real-world wireless attacks: drone-based evil twin infiltrations and APT lateral movement through neighboring networks
    • Why IoT devices get excluded from pen tests — and why that's a dangerous cycle
    • How AI is already being weaponized to accelerate wireless attacks
    • The one thing every security team should do today to close the wireless gap

    Subscribe to our LinkedIn to never miss news, updates, and quizzes to earn digital badges.

    • https://ztjourney.com
    • LinkedIn
    • YouTube

    Disclaimer: The views expressed are those of the speakers.

    続きを読む 一部表示
    14 分
  • Episode 47: The "Messy Middle" of AI Security: Why Agents Fail in Production
    2026/05/24

    In this episode of the Zero Trust Journey, Dr. Victor Monga sits down with Vishwas Manral, Founder and CEO of Precize Inc. and a major contributor to the Cloud Security Alliance (CSA).

    We dive deep into the "messy middle" of AI in cybersecurity. While AI has revolutionized how fast we can find and fix vulnerabilities, the critical gap of assessing business impact and understanding enterprise context remains a congested, single-lane freeway.

    What You’ll Learn:
    ◈ The "Messy Middle": Why a lack of business context is the primary bottleneck slowing down AI automation.
    ◈ Agentic Automation Risks: Why moving autonomous agents from a POC lab to production is incredibly risky without proper data hygiene.
    ◈ The Context Gap: Why having the smartest LLMs means nothing if your enterprise data is fragmented, outdated, or unstructured.
    ◈ Decision as a Service: The inevitable shift from SaaS to DaaS and the massive opportunity in building a true context fabric for your enterprise.

    Key Moments:
    00:00 ➔ Introduction: AI's missing link and the problem with Business Impact Analysis.
    02:05 ➔ The "Messy Middle": Finding problems vs. taking API-driven action.
    05:28 ➔ Extrapolating Data: Why a single LLM isn't enough to understand unique corporate environments.
    07:01 ➔ The 10% Confidence Gap: Why most automation gets permanently stuck in the test lab.
    11:01 ➔ The Hygiene Problem: Why an autonomous agent might accidentally nuke your production environment.
    16:13 ➔ THE QUOTE: "We are moving from software as a service to a decision as a service."

    🎙️ Meet the Guest:
    Vishwas Manral is the Founder and CEO of Precize Inc. A serial entrepreneur and leading mind in cybersecurity, Vishwas has a proven track record of seeing the next big industry problem and building the exact technology needed to solve it. His current focus is on building the context fabric required to make AI and agentic workflows safe for enterprise production environments.
    ➔ LinkedIn: https://www.linkedin.com/in/vishwasmanral/

    Subscribe to our LinkedIn to never miss news, updates, and quizzes to earn digital badges.

    • https://ztjourney.com
    • LinkedIn
    • YouTube

    Disclaimer: The views expressed are those of the speakers.

    続きを読む 一部表示
    17 分
  • Episode 46: Navigating Third-Party Risk and Continuous Monitoring
    2026/04/12

    In this episode, host Tiernan O'Malley sits down with Rachel Curran, GRC practitioner and founder of Locktivity, to unpack the complexities of Governance, Risk, and Compliance (GRC) in a cloud-first world.

    We dive deep into why third-party risk management cannot just be a "check-the-box" compliance exercise and how organizations must shift their focus from merely assessing vendors to actively managing how they interact with them.

    What You’ll Learn:
    ◈ The Fallacy of the Checklist: Why passing an audit doesn't automatically equal operational security.
    ◈ Continuous vs. Point-in-Time: The true value of SOC 2 audits and where continuous monitoring actually needs to step in (like catching missing 2FA).
    ◈ Quantifying Risk for Leadership: How to move beyond dollar amounts and make cyber risk personal and relatable to the C-suite.
    ◈ Silent Attack Vectors: The danger of stale OAuth tokens, unenforced SSO, and secrets left in commit histories.

    Key Moments:
    02:40 ➔ The Breach Reality: Why assessing vendors to completely avoid breaches is impossible, and why impact mitigation is the real goal.
    05:43 ➔ The Snowflake Example: How point-in-time audits often miss critical dynamic configurations like 2FA.
    10:53 ➔ Personalizing the Threat: How agentic AI integrations exposed a CEO's tax history—and why that changes the security conversation.
    16:36 ➔ The OAuth Danger: Why leaving unused OAuth tokens active is like leaving your front door open while on vacation.
    18:34 ➔ Warning Signs: How M&A activity, mass layoffs, and vendor evasiveness can predict upcoming security risks.

    🎙️ Meet the Guest:
    Rachel Curran is a GRC practitioner with over a dozen years of experience building SOC 2 and ISO security programs for startups. She is the founder of Locktivity, a platform focused on helping companies understand where their true third-party risk lies and how to proactively limit impact.
    ➔ LinkedIn: Rachel Curran
    ➔ Locktivity: locktivity.com

    About the Host:
    Host: Tiernan OMalley, Framework Security

    Subscribe to our LinkedIn to never miss news, updates, and quizzes to earn digital badges.

    • https://ztjourney.com
    • LinkedIn
    • YouTube

    Disclaimer: The views expressed are those of the speakers.

    続きを読む 一部表示
    23 分
  • Episode 45: From the Courtroom to the Boardroom: Cyber Resilience & Executive Accountability
    2026/04/03

    In this episode of the Zero Trust Journey, Dr. Victor Monga sits down with Erin Logue Smith, leader of Governance, Risk, and Cyber Strategy at World Wide Technology (WWT).

    We dive deep into the dangerous gap between checking the compliance box and achieving actual security, how the regulatory landscape is shifting to hold executives personally accountable, and how a legal background investigating faulty convictions translates into building robust cyber resilience.

    What You’ll Learn:
    ◈ Compliance vs. Safety: Why having regulatory frameworks in place doesn't automatically mean your organization is secure from a breach.
    ◈ The Executive Friction: How to handle C-suite pushback when security protocols clash with user convenience.
    ◈ The Cyber Insurance Shift: Why brokers are getting smarter, utilizing AI gap analysis, and demanding tabletop exercises before underwriting policies.
    ◈ The Investigative Edge: How analyzing evidence at the Innocence Project directly mirrors uncovering the root causes of a devastating cyber incident.

    Key Moments:
    02:49 ➔ The C-Suite Problem: When executives want security on paper but refuse to adopt the friction themselves.
    05:06 ➔ The Accountability Era: Why the SEC and boards are firing executives for claiming "I didn't know."
    07:47 ➔ Insurance Brokers Level Up: Why the days of insurers blindly paying out for preventable breaches are over.
    11:17 ➔ Courtroom to Boardroom: How an investigative legal mindset sets you apart in the cybersecurity industry.

    🎙️ Meet the Guest:
    Erin Logue Smith leads Governance, Risk, and Cyber Strategy at World Wide Technology (WWT). With a unique foundation holding a JD and early career experience at the DA's office and the Innocence Project, Erin brings an unparalleled investigative and regulatory perspective to cybersecurity. She previously served as a Field CTO at Dell Technologies specializing in cyber resilience and spent a decade managing international data privacy at PNC.
    ➔ LinkedIn: https://www.linkedin.com/in/erin-logue-smith

    Subscribe to our LinkedIn to never miss news, updates, and quizzes to earn digital badges.

    • https://ztjourney.com
    • LinkedIn
    • YouTube

    Disclaimer: The views expressed are those of the speakers.

    続きを読む 一部表示
    13 分
  • Episode 44: Stop Punishing, Start Rewarding: Mastering the P.A.R. Method for Phishing Defense
    2026/04/02

    In this episode of the Zero Trust Journey, Dr. Victor Monga sits down with Craig Taylor, former CISO at JP Morgan Chase and Vistaprint, and the founder of Cyber Hoot.

    We are throwing out the old playbook. If your security awareness program relies on "shocking" or punishing employees for clicking phishing links, you are fighting a losing battle. Craig explains why the future of cyber literacy lies in psychology, gamification, and giving employees the right tools to build muscle memory against AI-powered threats.

    What You’ll Learn:
    ◈ The Power of Rewards: Why behavioral psychology proves that positive reinforcement and gamification are far more effective than the traditional "three strikes" punishment model.
    ◈ Mastering the P.A.R. Method: How to train your workforce to Pause, Assess, and Report—turning a split-second reaction into a calculated defense mechanism.
    ◈ Solving Human Problems: Why we need to stop applying binary (0/1) IT solutions to complex human behaviors.
    ◈ AI-Powered Phishing: How attackers are using GenAI to create hyper-personalized lures, and why the P.A.R. method is your best defense against flawless social engineering.

    Key Moments:
    02:57 ➔ The Effectiveness Gap: Why annual compliance training shows zero correlation with reduced phishing failures.
    06:07 ➔ The "Dog Training" Analogy: What B.F. Skinner can teach us about using rewards over punishments in cybersecurity.
    07:11 ➔ THE QUOTE: "We are trying to solve a human problem with zero one binary solutions."
    12:41 ➔ Building Muscle Memory: How the Pause, Assess, Report (P.A.R.) framework stops AI-generated phishing in its tracks.

    🎙️ Meet the Guest:
    Craig Taylor is a seasoned cybersecurity leader and former CISO for organizations like JP Morgan Chase, Vistaprint, and Neoscope. Armed with a background in psychology and decades of IT experience, Craig founded Cyber Hoot, a learning management platform dedicated to re-engineering cyber literacy through positive reinforcement and behavioral science.

    ➔ LinkedIn: https://www.linkedin.com/in/craigmtaylor

    Subscribe to our LinkedIn to never miss news, updates, and quizzes to earn digital badges.

    • https://ztjourney.com
    • LinkedIn
    • YouTube

    Disclaimer: The views expressed are those of the speakers.

    続きを読む 一部表示
    16 分
  • Episode 43: Are You Talking to AI? Deepfakes, GANs, and the AI Security Menu
    2026/04/01

    We dive deep into the dark side of Generative AI, exploring how attackers are leveraging Generative Adversarial Networks (GANs) to bypass authentication, and why defining "AI Security" requires much more than just a buzzword.

    What You’ll Learn:
    ◈ Weaponized AI: How deepfakes, voice cloning, and AI note-takers are disrupting the identity perimeter and creating new insider threats.
    ◈ The User Burden: Why end-users inevitably bear the brunt of corporate security failures and the rising risk of synthetic identities.
    ◈ Zero Trust for AI: Strategies for isolating anomalies, maintaining visibility, and managing the risks of agentic AI.
    ◈ The AI Security Menu: Breaking down the 5 distinct types of AI security—from consuming commercial LLMs to building proprietary models.

    Key Moments:
    01:36 ➔ The Deepfake Threat: Why your voice could be used to bypass security protocols.
    09:59 ➔ Zero Trust vs. AI: The critical importance of visibility, discoverability, and continuous monitoring.
    12:26 ➔ Third-Party Risk Management for LLMs: Moving beyond basic vendor checks to test for prompt injection and token manipulation.
    14:48 ➔ The AI Security Menu: How to classify your AI risk footprint.
    08:04 ➔ THE QUOTE: "Even if you don't think you have an online presence, you do in some way."

    Subscribe to our LinkedIn to never miss news, updates, and quizzes to earn digital badges.

    • https://ztjourney.com
    • LinkedIn
    • YouTube

    Disclaimer: The views expressed are those of the speakers.

    続きを読む 一部表示
    20 分
  • Episode 42: Stop Thinking Servers, Start Thinking Systems
    2026/03/08

    In this episode of the Zero Trust Journey, Dr. Victor Monga is joined by Kayne McGladrey, a veteran systems engineer and CISSP who has spent his career securing high-stakes environments—from American Idol voting systems to defense industrial base firms.

    We move past the buzzwords to discuss the gritty reality of ripping out legacy "flat" networks and replacing them with Zero Trust architectures that actually improve performance while reducing liability. Kayne breaks down why the private sector continues to struggle with risk and how the rise of Agentic AI is changing the identity landscape in 2026.

    What You’ll Learn:
    ◈ The "Flat Network" Nightmare: Why open cable trays and unlabeled wires are a recipe for disaster.
    ◈ The Business of Trust: How to use Zero Trust as a competitive advantage to command premium pricing.
    ◈ Redefining "System": Why your web server isn't the system, but your accounts payable process is.
    ◈ AI and the "Circle of Failure": Navigating the FOMO of Agentic AI without giving root access to the unknown.
    ◈ Building Muscle Memory: Why the best incident response teams train like professional athletes.

    Subscribe to our LinkedIn to never miss news, updates, and quizzes to earn digital badges.

    • https://ztjourney.com
    • LinkedIn
    • YouTube

    Disclaimer: The views expressed are those of the speakers.

    続きを読む 一部表示
    16 分