CISO Series Podcast - podcast cover

CISO Series Podcast

David Spark, Mike Johnson, and Andy Elliscisoseries.com
Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.
Last refreshed:
Follow this podcast in the Metacast mobile app to refresh it and see new episodes.
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

It's a Little Hard to Evaluate New Solutions When You're Screaming "AI" at Me All the Time (Live in Houston)

All links and images can be found on CISO Series. This week's episode is hosted by David Spark , producer of CISO Series and Jerich Beason , CISO, WM . Joining them on stage is Jack Leidecker , CISO, Gong . This episode was recorded live at HOU SEC CON 2025 . In this episode: The open source sustainability problem AI levels the geopolitical playing field Cutting through AI vendor hype Why the fundamentals still hurt Thanks to Erik Bloch from Illumio for providing our "What's Worse" scenario. Hug...

Oct 28, 202544 min

Dear Abby: Why Should I Trust a Vendor Selling Me Zero Trust?

All links and images can be found on CISO Series. This week's episode is hosted by David Spark , producer of CISO Series and Dan Walsh , CISO, Datavant . Joining them is our sponsored guest, Rob Allen , chief product officer, ThreatLocker . In this episode: When EDR gets knocked out Red flags in vendor theater Configuration chaos The sticker problem Huge thanks to our sponsor, ThreatLocker ThreatLocker® Defense Against Configurations continuously scans endpoints to uncover misconfigurations, wea...

Oct 21, 202530 min

The Difference with AI Red Teaming is We Added the Word AI

All links and images can be found on CISO Series. This week's episode is hosted by David Spark , producer of CISO Series and Andy Ellis , principal of Duha . Joining us is our sponsored guest, Khush Kashyap , senior director, GRC, Vanta . In this episode: Skip the Sermon When to coach versus command Making risk quantification useful Recognizing a distinct discipline Huge thanks to our sponsor, Vanta Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and ...

Oct 14, 202538 min

Don't Worry, We'll Get to Solving Your Problem on Slide 87

All links and images can be found on CISO Series. This week's episode is hosted by David Spark , producer of CISO Series and Andy Ellis ( @csoandy ), principal of Duha. Joining them is Daniel Liber , CISO, Monday.com . In this episode: AI security's blind spot problem Vendors don't understand the assignment Marketing budgets overshadow actual innovation Accuracy versus effectiveness Huge thanks to our sponsor, Material Security Built specifically for Google Workspace, Material is a detection and...

Oct 07, 202537 min

Time to Choose a Security Vendor: Dart Board or Spin the Wheel?

All links and images can be found on CISO Series. This week's episode is hosted by David Spark , producer of CISO Series and Mike Johnson , CISO, Rivian . Joining them is Pavi Ramamurthy , global CISO and CIO, Blackhawk Network . In this episode: We can't promise safe, but we can promise ready Are we accidentally building security nightmares? Being held accountable for things you had no say in The safe space problem in vendor evaluation Huge thanks to our sponsor, Adaptive Security Sponsored by ...

Sep 30, 202544 min

Now That You Mention It I HAVE Heard Some Hype Around These AI Tools

All links and images can be found on CISO Series. This week's episode is hosted by David Spark , producer of CISO Series and Mike Johnson , CISO, Rivian . Joining them is Erwin Lopez , CISO, SLAC National Accelerator Laboratory . In this episode: The AI experimentation phase isn't optional When selling security becomes the hardest part of the job Threat actors aren't hacking in anymore We build, we bond, and we can't bear to let go Huge thanks to our sponsor, ThreatLocker Human error remains one...

Sep 23, 202534 min

Wait, SMS Doesn't Stand for "Super Mega Secure?"

All links and images can be found on CISO Series. This week's episode is hosted by David Spark , producer of CISO Series and Andy Ellis , principal of Duha. Joining us is our sponsored guest, Brian Long , CEO, Adaptive Security. In this episode: Hiring North Korean operatives on a Tuesday AI coding and the death of specifications Deepfake personas beyond video calls The middleman problem with SMS Huge thanks to our sponsor, Adaptive Security AI-powered social engineering threats like deepfake vo...

Sep 16, 202543 min

We All Agree That Prevention Is the Best Advice We're Never Going to Follow

All links and images can be found on CISO Series. This week's episode is hosted by David Spark , producer of CISO Series and Andy Ellis , principal of Duha. Joining us is Jason Loomis , CISO, Freshworks . In this episode: Making organizations take their security medicine Building CISO support systems Holding the door for humans Underappreciated risks: beyond the headlines Huge thanks to our sponsor, Safe Security SAFE is the category leader in Cyber Risk Quantification (CRQ) and the first vendor...

Sep 09, 202544 min

We're All for a Responsible AI Rollout as Long as It Goes as Fast as Possible

All links and images can be found on CISO Series. This week's episode is hosted by David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining them is Jennifer Swann, CISO, Bloomberg Industry Group. In this episode: Vulnerability management vs. configuration control Open source security and supply chain trust Building security leadership presence AI governance and enterprise risk Huge thanks to our sponsor, Vanta Vanta's Trust Management Platform automates key areas of your GRC ...

Sep 02, 202540 min

New Study Finds No Email Has Ever "Found You Well"

All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark , producer of CISO Series and Mike Johnson , CISO, Rivian . Joining us is David Cross , CISO, Atlassian . In this episode: Breaking the Sales Cycle Leadership Under Fire Predicting the Unpredictable Security Startups' Security Paradox A huge thanks to our sponsor, ThreatLocker ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses fro...

Aug 26, 202534 min

I Just Can't Communicate With the Business. I've Tried Condescension AND Derision.

All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark , producer of CISO Series and Andy Ellis ( @csoandy ), principal of Duha. Joining us is Gary Chan , CISO, SSM Health . Be sure to check out Gary's security mentalism website: https://www.gschan2000.com . In this episode: Decision-making with incomplete information Translation beats technical expertise Influence trumps authority for CISOs Technical prowess creates adversaries Huge thanks to our spon...

Aug 19, 202536 min

Impressive! Our AI is Approaching "One 9" of Accuracy.

All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark , producer of CISO Series and Andy Ellis ( @csoandy ), principal of Duha. Joining us is our sponsored guest, Kevin Tian , co-founder and CEO, Doppel. In this episode: AI fraud gets on the juice Agentic AI demands a new security mindset The new frontier for social engineering We still need human verification Huge thanks to our sponsor, Doppel Doppel is the first social engineering defense platform b...

Aug 12, 202540 min

They Can't Hack All Our Tools If We Keep Buying New Ones

All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark , producer of CISO Series and Mike Johnson , CISO, Rivian . Joining them is their sponsored guest, Rajan Kapoor , CEO of Material Security . In this episode: AI creates security's catch-22 Delegation without abandonment Google's security gaps demand better tools Trust beats sophistication every time A huge thanks to our sponsor, Material Security What if you could get a view of security across Goog...

Aug 05, 202534 min

Cosmo Quiz! 23 Ways to Make Your Vendors Obsessed With Your Security Standards

All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark , producer of CISO Series and Mike Johnson , CISO, Rivian . Joining us is our sponsored guest, Rob Allen , chief product officer, ThreatLocker . In this episode: Large enterprise security demands drive vendor improvements Technical expertise becomes leadership liability without delegation EDR evolution needs prevention focus Career breaks require personal ownership and strategic timing A huge thank...

Jul 29, 202539 min

We'll Worry About Recovering From the Attack Once We Ace This Audit

All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark , producer of CISO Series and Andy Ellis ( @csoandy ), partner, YL Ventures . Joining us is Peter Clay , CISO, Aireon . In this episode: Purple teaming evolution misses operational realities Effective postmortems require systematic failure analysis Risk expertise requires business context over methodology Compliance and resilience serve different purposes Huge thanks to our sponsor, Safe Security S...

Jul 22, 202543 min

Once You Memorize the Manual, Our User Interface is Very Intuitive

All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark , producer of CISO Series and Andy Ellis ( @csoandy ), principal, Duha . Joining us is our sponsored guest, Edward Wu , CEO and founder, Dropzone AI . In this episode: Building context-aware verification frameworks Understanding why UX fails Moving beyond AI replacement narratives Building for a crisis A huge thanks to our sponsor, Dropzone AI Dropzone AI autonomously investigates every security al...

Jul 15, 202539 min

Not Enough Hallucinations? Let's Outfit Your LLM with Another LLM

All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark , producer of CISO Series and Edward Contreras , senior evp and CISO, Frost Bank . Joining us is Anthony Candeias , CISO, Weight Watchers. In this episode: AI agents require structured supervision, not autonomy Hiring for potential over credentials in cybersecurity AppSec training effectiveness depends on organizational relevance AI oversight requires purpose-built models, not general solutions A h...

Jul 08, 202536 min

We Require 3-5 Years of Experience to Qualify for the Cyber Skills Shortage

All links and images can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark , the producer of CISO Series , and Mike Johnson , CISO, Rivian . Joining us is Anne Marie Zettlemoyer , former vp of security, Activision Blizzard. In this episode SOC automation: Moving beyond alert fatigue The entry-level security talent reality Learning from security incidents without blame Evaluating security vend...

Jul 01, 202538 min

We Can Either Build Resilience or Just Always Be Perfect

All links and images can be found on CISO Series . This week's episode is hosted by me, David Spark , producer of CISO Series and Edward Contreras , senior evp and CISO, Frost Bank . Joining us is Ryan Bachman , executive vice president and CISO, GM Financial . In this episode Identity consolidation versus simplification Entry-level pathways into cybersecurity Evolution of the CISO role toward business resilience Applying simplification principles to cybersecurity complexity Huge thanks to our s...

Jun 24, 202538 min

We Checked the "Yes" Box for Cybersecurity. What Else Do We Have to Do?

All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark ( @dspark ), producer of CISO Series and Andy Ellis ( @csoandy ), partner, YL Ventures . Joining us is Alex Hall, CISO, Gensler. In this episode: Evaluating secure messaging beyond the app Reframing compliance as a business enabler Incremental security investment vs. crisis response Why culture, not punishment, drives secure behavior Huge thanks to our sponsor, Vanta Automate, centralize, & sca...

Jun 17, 202541 min

Aside From Text, Images, and Videos, GenAI Can't Fool Me (Live in Boston)

All links and images can be found on CISO Series . This week's episode is hosted by me, David Spark , producer of CISO Series and Andy Ellis , partner, YL Ventures . Joining us is our sponsored guest, Sam Curry , global vp, CISO at Zscaler . This episode was recorded at a Zscaler event in Boston, MA. In this episode: Guardrails for decision making under fatigue Preparing for quantum threats Strategic use of generative AI Reassessing outdated knowledge Huge thanks to our sponsor, Zscaler Zscaler ...

Jun 10, 202547 min

AI Isn't Going to Take Your Job, It's Going to Eliminate It! (LIVE at BSidesSF)

All images and links can be found on CISO Series. This week's episode is hosted by me, David Spark ( @dspark ), producer of CISO Series and Andy Ellis ( @csoandy ), partner, YL Ventures . Joining us is Alexandra Landegger , global head of cyber strategy & transformation, RTX . In this episode: A cybersecurity fast-track? When Ambition Becomes a Liability Giving the CVE Program the Credit It Deserves Elevating human cyber talent with AI Huge thanks to our sponsors, Nudge Security, SecuritySco...

Jun 03, 202545 min

I Can't Choose. I Love All My Assets Equally.

All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark ( @dspark ), producer of CISO Series and Andy Ellis ( @csoandy ), partner, YL Ventures . Joining us is Tim Jacobs , vp, CISO, Commonwealth Care Alliance . In this episode: Starting from zero Prepare for decisive decisions Working back from unacceptable Discovering inefficiencies A huge thanks to our sponsor, ThreatLocker ThreatLocker® is a global leader in Zero Trust endpoint security, offering cyb...

May 27, 202534 min

Why Learn Security Fundamentals When We Could Just Chase Our Tails?

All links and images for this episode can be found on CISO Series . I host this week's episode, David Spark ( @dspark ), producer of CISO Series and Jesse Whaley , CISO, Amtrak . Joining them is their guest Vaughn Hazen , CISO, CN . In this episode: The classics endure The rules of the rail "Prove It. With data." It's all just software A huge thanks to our sponsor, Doppel Doppel is the first social engineering defense platform built to dismantle deception at the source. It uses AI and infrastruc...

May 20, 202534 min

I'm Not Looking Down at You, I'm Looking Down at What You're Doing

All links and images for this episode can be found on CISO Series . This week's episode is hosted by me, David Spark ( @dspark ), producer of CISO Series and Andy Ellis ( @csoandy ), partner, YL Ventures . Joining us is our sponsored guest, Saket Modi , co-founder and CEO, SAFE Security . In this episode: Elevating AI to table stakes Security for the real world Using dynamic models for TPRM The agentic AI augmentation Huge thanks to our sponsor, SAFE Security SAFE (#1 platform to unify the manag...

May 13, 202542 min

They're Not AI Mistakes, They're Happy Little Incidents

All links and images for this episode can be found on CISO Series . This week's episode is hosted by me, David Spark , producer of CISO Series, and Andy Ellis , partner of YL Ventures . Their sponsored guest is Jadee Hanson , CISO of Vanta . In this episode: Find a partner to work with Fixing the root of burnout The limitations of human vigilance Balancing openness and control Thanks to our sponsor, Vanta. Automate, centralize, & scale your GRC program with Vanta Vanta's Trust Management Pla...

May 06, 202546 min

Get ALL the Challenges of Cybersecurity AND Fewer Resources

All links and images for this episode can be found on CISO Series . This week's episode is hosted by me, David Spark , producer of CISO Series, and Mike Johnson , CISO, Rivian . Joining us is Charles Blauner , formerly of Team8 (at time of recording) and now operating partner, Crosspoint Capital . In this episode: Expanding collective defense Getting talent to the municipal level A mature reporting structure A pill for that cyberailment Huge thanks to our sponsor, Material Security Material Secu...

Apr 29, 202540 min

Data Minimization Means We Don't Tell You What We're Collecting

All links and images for this episode can be found on CISO Series . This week's episode is hosted by me, David Spark , producer of CISO Series, and Andy Ellis , partner, YL Ventures . Joining us is Mandy Huth , svp, CISO, Ultra Clean Technology . In this episode: Start with good defaults Building talent bridges Don't forget the humans Differentiating with privacy Automate, centralize, & scale your GRC program with Vanta Vanta's Trust Management Platform automates key areas of your GRC progra...

Apr 22, 202542 min

Welcome to Cybersecurity: Where Everything Is Made Up and the Points Don't Matter

All links and images for this episode can be found on CISO Series . This week's episode is hosted by me, David Spark , producer of CISO Series and Andy Ellis , partner, YL Ventures . Joining us is Mike D'Arezzo , executive director of infosec and GRC, Wellstar Health Systems . In this episode: The shift left myth Reconsidering CISO evaluations The power of "how" Building bridges Huge thanks to our sponsor, ThreatLocker ThreatLocker® is a global leader in Zero Trust endpoint security, offering cy...

Apr 15, 202541 min

With AI, Don't Think Like a Hacker, Think Like the Whole of Society

All links and images for this episode can be found on CISO Series . This week's episode is hosted by me, David Spark , producer of CISO Series and Andy Ellis , partner, YL Ventures . Joining us is our sponsored guest Nathan Hunstad , director, security at Vanta . In this episode: Thinking like AI Building off a solid foundation Start with ownership Following the leader Big thanks to our sponsor, Vanta Automate, centralize, & scale your GRC program with Vanta. Vanta's Trust Management Platfor...

Apr 08, 202539 min
Hosted on Libsyn
For the best experience, listen in Metacast app for iOS or Android