CISO Series Podcast - podcast cover

CISO Series Podcast

David Spark, Mike Johnson, and Andy Elliscisoseries.com
Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.
Last refreshed:
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

All links and images can be found on CISO Series This week's episode is hosted by David Spark , producer of CISO Series and Andy Ellis , principal of Duha. Joining is our sponsored guest, Danny Jenkins , CEO, ThreatLocker . In this episode: Permission creep at machine speed The pattern we keep calling a mistake Stop authenticating the human Vibe coded out of existence A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verif...

Jun 09, 202644 min

Our Data Security Policy Is Transparent in That It Doesn't Exist

Our Data Security Policy Is Transparent in That It Doesn't Exist All links and images can be found on CISO Series This week's episode is hosted by David Spark , producer of CISO Series, and Mike Johnson , CISO, Rivian . Joining is Mike Melo , CISO, TMX Group . In this episode: The weight of old controls Data you can actually see 68 vendors and counting Authority you never had to claim A huge thanks to our sponsor, Vanta Still stuck on the quarterly audit treadmill? Meet Calm-pliance. Vanta combi...

Jun 02, 202638 min

If You Love Cloud Misconfigurations So Much, Why Don't You Marry Them!

All links and images can be found on CISO Series This week's episode is hosted by David Spark , producer of CISO Series, and Andy Ellis , principal of Duha. Joining them is their sponsored guest Amit Megiddo , CEO and founder, Native . In this episode: The CISO you don't need Misconfigurations aren't a cloud problem Secure by design means enforcing it Finding bugs faster isn't the bottleneck A huge thanks to our sponsor, Native Native makes secure-by-design inherent to how the cloud operates. It...

May 26, 202640 min

Why Be Responsible When We Can Just Blame AI?

All links and images can be found on CISO Series This week's CISO Series Podcast features David Spark, producer of CISO Series, and Andy Ellis , principal of Duha . Joining us is our sponsored guest, Jadee Hanson , CISO, Vanta. In this episode: The compliance receipt nobody reads Who signs off on the AI that wrote the code The agent that wouldn't stop The questionnaire that should not exist A huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security ...

May 19, 202642 min

Can You Please Train the AI on Your Way Out the Door?

All links and images can be found on CISO Series This week's episode is hosted by David Spark , producer of CISO Series and Mike Johnson , CISO, Rivian . Joining is Jean-Paul Calabio , vp and CISO, Grainger . In this episode: Scanning the map isn't securing the territory CFOs don't fund faith What your AI inherits Nobody owns the gap Thanks to Jonathan Waldrop, CISO, Acoustic for providing our "What's Worse" scenario. A huge thanks to our sponsor, ThreatLocker ThreatLocker makes Zero Trust pract...

May 12, 202637 min

AI Confidence: It's a Trap! (LIVE in San Francisco)

All links and images can be found on CISO Series This week's episode is hosted by David Spark , producer of CISO Series and Mike Johnson , CISO, Rivian . Joining is Sara Madden , CISO, Convera . This episode was recorded live at BSidesSF 2026. In this episode: Playing vendor roulette Confident and wrong Making conferences count The stakes problem in tabletops A huge thanks to our sponsor, QuilrAI Can you tell if an action in your environment was performed by a human — or an AI agent? QuilrAI's D...

May 05, 202643 min

Step 1: Deploy New AI Tool. Step 2: Discover Security Flaws. Step 3: Repeat. (LIVE in Orlando)

All links and images can be found on CISO Series This week's episode is hosted by David Spark , producer of CISO Series and Michelle Wilson , CISO, Movement Mortgage . Joining is sponsored guest Rob Allen , chief product officer, ThreatLocker . This show was recorded in front of a live audience at ThreatLocker's conference, Zero Trust World 2026. In this episode: Risk as a daily habit AI agents talking to AI agents The code on the lock Words that shape decisions A huge thanks to our sponsor, Thr...

Apr 28, 202643 min

Back in My Day, You Could Get a Cybersecurity Job at the Corner Store

All links and images can be found on CISO Series This week's episode is hosted by David Spark , producer of CISO Series and Andy Ellis , principal of Duha. Joining is Paul Drapeau , head of global information security, New Balance . In this episode: The logo trap Immunity through exposure The synthesis edge The cost of holding tight A huge thanks to our sponsor, Doppel This episode is sponsored by Doppel, the AI-native social engineering defense platform. Doppel strengthens human risk management...

Apr 21, 202640 min

Our Theoretical Controls Work Great Against Hypothetical Attacks

Our Theoretical Controls Work Great Against Hypothetical Attacks All links and images can be found on CISO Series This week's episode is hosted by David Spark , producer of CISO Series and Andy Ellis , principal of Duha. Joining is David Nolan , former CISO, Asurion. In this episode: Influence, not control The initiative gap Skip the framework, patch the server Confident code with no owner A huge thanks to our sponsor, ThreatLocker ThreatLocker makes Zero Trust practical. With Default Deny, Ring...

Apr 14, 202643 min

Remember, Every Underappreciated Risk Is Just a Crisis Waiting to Be Discovered

All links and images can be found on CISO Series . This week's episode is hosted by me, David Spark , producer of CISO Series and Andy Ellis , principal of Duha. Joining us is Hilik Kotler , svp, CISO and IT, Expedia Group . In this episode: The numbers game What makes a vendor worth your time Humanity in the loop Alignment is a prerequisite, not a nice-to-have A huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's a...

Apr 07, 202643 min

Do You Think These Compliance Boxes Check Themselves? (LIVE in Clearwater, FL)

All links and images can be found on CISO Series . This week's episode is hosted by David Spark , producer of CISO Series and Pam Lindemoen , CSO, vp of strategy, Retail and Hospitality-ISAC . Joining them is Jason Mayor , deputy CISO, Raymond James Financial . This episode was recorded in front of a live audience at the National Cybersecurity Alliance's Convene conference in Clearwater, Florida. In this episode: Coaching security Planned security theater Making "nothing bad happened" a compelli...

Mar 31, 202644 min

Why Highlight Diversity When We Can Just Hope You Don't Notice?

All links and images can be found on CISO Series . This week's episode is hosted by David Spark , producer of CISO Series and Mike Johnson , CISO, Rivian . Joining is Julie Myerholtz , CISO, Brunswick Corporation . In this episode: Your cloud, your problem Kill your sacred cows AI broke your vendor math Feedback is a gift. Open it. A huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, r...

Mar 24, 202638 min

They're Less "Best Practices" and More "Sounds Good on LinkedIn"

All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark , producer of CISO Series and Andy Ellis , principal of Duha. Joining us is Rebecca Harness , CISO, Deltek . In this episode: Let it fail The CIO seat is empty. Now what? Design for how people actually work "We found 23 issues. That'll be $15,000." Huge thanks to our sponsor, Strike48 Strike48 is the Agentic Log Intelligence Platform that actually puts AI agents to work, combining full log visibili...

Mar 17, 202642 min

It's Okay to Put All Your Eggs in One Basket as Long as You Really Trust the Basket

All links and images can be found on CISO Series . This week's episode is hosted by me, David Spark , producer of CISO Series and Andy Ellis , principal of Duha. Joining us is our sponsored guest, Rob Allen , chief product officer, ThreatLocker . In this episode: Your best employee is your biggest risk Stop guessing the next attack AI is not a feature Stop blaming the user Huge thanks to our sponsor, ThreatLocker ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevat...

Mar 10, 202648 min

Our Security Team's Love Language is Buying New Tools

All links and images can be found on CISO Series . This week's episode is hosted by me, David Spark , producer of CISO Series and Andy Ellis , principal of Duha. Joining us is our sponsored guest, Tim Leehealey , vp of corporate strategy and operations, Strike48 . In this episode: Defensible, not perfect Tools aren't going to save you Logs are wasted on the SOC The myth of the lone wolf Huge thanks to our sponsor, Strike48 Strike48 is the Agentic Log Intelligence Platform that actually puts AI a...

Mar 03, 202641 min

If We Can't Do Better, at Least Do It Faster

All links and images can be found on CISO Series . This week's episode is hosted by David Spark , producer of CISO Series and Andy Ellis , principal of Duha. Joining them is Vikas Mahajan , vp and CISO, American Red Cross . In this episode: Questionnaires aren't risk management The good old days were worse Buying or building your SOC Start the conversation, not the checklist Huge thanks to our sponsor, Adaptive Security Sponsored by Adaptive Security—the first cybersecurity company backed by Ope...

Feb 24, 202642 min

We Gave the CISO Risk and Liability, and Now They Want Authority. The Nerve.

All links and images can be found on CISO Series . This week's episode is hosted by David Spark , producer of CISO Series and Steve Zalewski . Joining them is Tammy Klotz , CISO, Trinseo . In this episode: Accountability without authority Kill your hacklore Voice is no longer enough Studies that tell us what we already know Huge thanks to our sponsor, ThreatLocker Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement an...

Feb 17, 202642 min

When We See White Smoke, We Know We Have a New CISO

All links and images can be found on CISO Series . This week's episode is hosted by David Spark , producer of CISO Series and Andy Ellis , principal of Duha. Joining them is Russ Ayres , CISO, Principal Financial Group . In this episode: Metrics that matter Tool babysitting problem Automating the brokenness Stay connected intentionally Huge thanks to our sponsor, Strike48 Strike48 is the Agentic Log Intelligence Platform that actually puts AI agents to work, combining full log visibility with AI...

Feb 10, 202643 min

Take Two-Factor Authentication and Call Me in the Morning

All links and images can be found on CISO Series. This week's episode is hosted by David Spark , producer of CISO Series, and Andy Ellis , principal of Duha. Joining them is Janet Heins , CISO, ChenMed . In this episode: Inbound gets ignored Independence under constraint Methodology means nothing Lives over logins Huge thanks to our sponsor, Guardsquare Guardsquare delivers mobile app security without compromise, providing advanced protections for both Android and iOS apps. From app security tes...

Feb 03, 202639 min

I'll Show You Our Resilience Plan Once Our Cloud Storage Is Back Online

All links and images can be found on CISO Series. This week's episode is hosted by David Spark , producer of CISO Series and Mike Johnson , CISO, Rivian . Joining them is Johann Balaguer , Global CISO, Hard Rock Hotels and Casinos . In this episode: Understanding the why Own your digital self Invest beyond tenure Prepare for dependencies Thanks to Louis Zhichao Zhang, AIA Australia for contributing this week's "What's Worse?!" scenario. Huge thanks to our sponsor, Guardsquare Guardsquare deliver...

Jan 27, 202638 min

AI Is Very Efficient at Making Us Forget the Value of Humans

All links and images can be found on CISO Series. This week's episode is hosted by David Spark , producer of CISO Series and Andy Ellis , principal of Duha. Joining them is Sara Madden , CISO, Convera . In this episode: Hold developers accountable Credibility through candor Be strategic with AI deployment Resources don't guarantee security Huge thanks to our sponsor, ThreatLocker ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real contro...

Jan 20, 202641 min

Managing Risk Has Been a Priority Ever Since You Asked About It (LIVE in NYC)

All links and images can be found on CISO Series. This week's episode is hosted by David Spark , producer of CISO Series and Matthew Southworth , CSO, Priceline . Joining them is sponsored guest, Saket Modi , CEO, Safe Security . This episode was recorded live at FAIRCON25 in NYC. In this episode: AI won't stay broken Identity before intelligence People decide risk appetite Automate with oversight Huge thanks to our sponsor, Safe Security SAFE is the leader in Cyber Risk Quantification and the f...

Jan 13, 202641 min

Imagine Scaling Mistakes 5x Faster. Thank You, Automation! (LIVE in NY)

All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark , producer of CISO Series and Matt Southworth, CISO, Priceline. Joining us is our sponsored guest, Leslie Nielsen, CISO, Mimecast. In this episode: Automating dysfunction Leading without dominating Unglamorous wins Code without comprehension Huge thanks to our sponsor, Mimecast. Cyber threats are getting smarter every day, and threat actors aren't just targeting your technology, they're targeting y...

Jan 06, 202644 min

How Much Risk Would a CISO Risk if a CISO Could Risk Risk? (LIVE in Boca Raton)

All links and images can be found on CISO Series. This week's episode is hosted by David Spark , producer of CISO Series and Brett Conlon , CISO, American Century Investments . Joining them are Ryan Barras , CISO, Mount Sinai Medical Center . In this episode: Nobody understands what we do Someone else should fix this Make the audience care Speaking CEO Huge thanks to our sponsor, Dropzone AI Dropzone AI autonomously investigates every security alert—no playbooks needed. This AI SOC analyst queri...

Dec 16, 202545 min

I'm Worried That We're Not Worried About the Right Worries With AI

All links and images can be found on CISO Series. This week's episode is hosted by David Spark , producer of CISO Series and Mike Johnson , CISO, Rivian . Joining them is their sponsored guest, Danny Jenkins , CEO, ThreatLocker . In this episode: AI for AI's sake Stop selling, start protecting Stop calling everything sophisticated Least privilege, rebranded Huge thanks to our sponsor, ThreatLocker ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CIS...

Dec 09, 202540 min

You Can't Fall Behind in AI if You Never Start

All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark , producer of CISO Series, and Mike Johnson , CISO, Rivian . Joining us is John Barrow , CISO, JB Poindexter & Co. In this episode: Building unicorns, not hunting them Cold War frameworks for modern threats Trading dollars for stories Mirror, mirror on the wall Huge thanks to our sponsor, Vanta Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and stre...

Dec 02, 202535 min

Why Architect for Human Error When We Can Make People Feel Really Bad About It?

All links and images can be found on CISO Series. This week's episode is hosted by David Spark , producer of CISO Series and Andy Ellis ( @csoandy ), principal of Duha. Joining them is Richard Rushing , CISO, Motorola Mobility . In this episode Mindset over tools When hygiene becomes risk Systems for actual humans Conversations over compliance Huge thanks to our sponsor, ThreatLocker ThreatLocker® Defense Against Configurations continuously scans endpoints to uncover misconfigurations, weak fire...

Nov 25, 202539 min

Are You Implying This Line Graph Isn't a Compelling Cybersecurity Narrative?

All links and images can be found on CISO Series. This week's episode is hosted by David Spark , producer of CISO Series and Andy Ellis ( @csoandy ), principal of Duha. Joining them is our sponsored guest, Nathan Hunstad , director, security, Vanta . In this episode: Metrics that matter Testing for real AI as an assistant Intelligence without context Huge thanks to our sponsor, Vanta Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the ...

Nov 18, 202541 min

Our CISO Certainly Puts the Tool in Multi-Tool (LIVE in LA)

All links and images can be found on CISO Series. This week's episode is hosted by David Spark , producer of CISO Series and Jeff Steadman , deputy CISO, Corning Incorporated . Joining them is Quincey Collins , CSO, Sheppard Mullin . This episode was recorded live at the ISSA LA Summit in Santa Monica, California. In this episode: The foundational debate Strength over breadth Beyond traditional backgrounds Keeping perspective on risk Huge thanks to our sponsors, Adaptive Security and Dropzone AI...

Nov 11, 202545 min

I Don't Just Guess About Effectiveness, I Make Educated Guesses!

All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark , producer of CISO Series and Andy Ellis ( @csoandy ), principal of Duha. Joining us is Sara Madden , CISO, Convera . In this episode: Optimizing for reality, not idealism Engineering governance instead of monitoring compliance When AI finds what humans miss The measurement problem Huge thanks to our sponsor, ThreatLocker Human error remains one of the top cybersecurity threats. Just one wrong clic...

Nov 04, 202539 min
Hosted on Libsyn
For the best experience, listen in Metacast app for iOS or Android