Defense in Depth - podcast cover

Defense in Depth

David Spark, Steve Zalewski, Geoff Belknapcisoseries.com
Defense in Depth promises clear talk on cybersecurity’s most controversial and confusing debates. Once a week we choose one controversial and popular cybersecurity debate and use the InfoSec community’s insights to lead our discussion.

Episodes

Do Companies Undergoing a Merger or Acquisition Get Targeted for Attacks?

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Christina Shannon , CIO, KIK Consumer Products . Joining us is Andrew Cannata , CISO, Primo Water . In this episode: The lure of an IPO is debatable Does an IPO make you a target or just more vulnerable? M&A changes your context Ambiguity creates risk Than...

Jul 18, 202427 min

Telling Stories with Security Metrics

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Steve Zalewski . Joining us is our sponsored guest, Shirley Salzman , CEO and co-founder, SeeMetrics . In this episode: Finding the purpose in metrics Using metrics to answer business questions Speaking to your audience Communication is a two-way street Th...

Jul 11, 202431 min

Securing Identities in the Cloud

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ). Joining us is our sponsored guest, Adam Bateman , CEO, Push Security . The SaaS attacks matrix community resource mentioned by Adam in the episode can be found here . Editorial note: Geoff Belknap is an advisor to Push Secu...

Jun 27, 202433 min

How AI Is Making Data Security Possible

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Steve Zalewski . Joining us is our sponsored guest, Lamont Orange , CISO, Cyera . In this episode: The data security check has come due Putting data security at the heart of defense in depth Automation is key You need to know what you’re protecting Thanks ...

Jun 20, 202428 min

What Makes a Successful CISO?

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Christina Shannon , CIO, KIK Consumer Products . Joining us is our guest, Tomer Gershoni , CSO, Zoominfo . In this episode: Moving beyond technology The art of a CISO CISOs always operate in context Elevating the CISO conversation Thanks to our podcast spo...

Jun 13, 202434 min

We Want a Solution to Remediate, Not Just Detect Problems

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Yaron Levi , CISO, Dolby . Joining us is our guest, Neil Watkins , svp technology and cybersecurity services, i3 Verticals . In this episode: Visibility doesn’t matter without context Not all visibility is created equal Don’t forget to bring people into th...

Jun 06, 202425 min

Recruiting from the Help Desk

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, LinkedIn . Joining me is our guest, Sasha Pereira , vp of infrastructure and CISO, WASH . In this episode: Is working the help desk a great place to get entry level cyber security skills? So why is it so often overloo...

May 30, 202430 min

How Do We Build a Security Program to Thwart Deepfakes?

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, LinkedIn . Joining us is our guest, Russ Ayers , svp of cyber & deputy CISO, Equifax . In this episode: Are we seeing AI and LLM rapidly push into what was science fiction into production? What happens as our ability ...

May 23, 202429 min

Where Are Secure Web Gateways Falling Short?

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Steve Zalewski . Joining us is our sponsored guest, Vivek Ramachandran , founder, SquareX . In this episode: Are secure web gateways still an effective tool in the enterprise? As the browser has changed a lot in the last decade, are Secure Web Gateways - S...

May 16, 202428 min

Understanding the Zero-Trust Landscape

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, LinkedIn . Joining me is our guest Richard Stiennon , chief research analyst, IT-Harvest. In this episode: In this episode: Why do so many vendors claim to offer zero-trust solutions? Is that framework even applicable...

May 09, 202431 min

Scaling Least Privilege for the Cloud

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, LinkedIn . Joining us is our sponsored guest, Sandy Bird , co-founder and CTO, Sonrai Security . In this episode: Why does scaling least privilege in the cloud remain challenging? Is throwing more people at the proble...

May 02, 202435 min

Should CISOs Be More Empathetic Towards Salespeople?

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, LinkedIn . Joining me is our guest, Emily Heath , general partner, Cyberstarts . In this episode: How do CISOs feel about sales pitches? Do they have legitimate complaints? When do these legitimate complaints cross th...

Apr 25, 202435 min

Managing Data Leaks Outside Your Perimeter

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, LinkedIn . Joining me is our sponsored guest, Mackenzie Jackson , developer advocate, GitGuardian . In this episode: How to manage data leaks outside your perimeter? When data leaks increasingly come from third-partie...

Apr 18, 202430 min

What Are the Risks of Being a CISO?

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, LinkedIn . Joining me is our guest, Phil Davis , attorney, healthcare cybersecurity and privacy, Hall Render . In this episode: In today's current climate, is the role of the CISO still worth it? Does the position car...

Apr 11, 202436 min

Onboarding Security Professionals

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, LinkedIn . Joining me is our guest, Paul Connelly , former CISO, HCA Healthcare Got feedback? In this episode: How important is onboarding new cyber talent? Does it set the tone for their tenure with your organization...

Apr 04, 202431 min

How to Improve Your Relationship With Your Boss

All links and images for this episode can be found on CISO Series . Check out this post Monte Pedersen of The CDA Group for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, LinkedIn . Joining us is our guest, Jerry Davis , division director for cyber defense at Truist Bank . In this episode: Why does advancing your career require more than just technical s...

Mar 28, 202429 min

Improving the Responsiveness of Your SOC

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Steve Zalewski . Joining me is our sponsored guest, Spencer Thompson , CEO, Prelude . In this episode: Why does it take so long to integrate new tools and get them up to speed? Are we always in a state where we are always lacking readiness? What should we ...

Mar 21, 202428 min

The Demand for Affordable Blue Team Training

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Steve Zalewski . Joining me is our guest, Ron Gula , president and co-founder, Gula Tech Adventures . In this episode: Why is it so darn expensive to get any training on the defender side? Why is there a mountain of free education for red teaming? Shouldn’...

Mar 14, 202429 min

Why are CISOs Excluded from Executive Leadership?

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, LinkedIn . Joining me is our guest, Ben Sapiro , head of global cyber security services, Manulife . In this episode: Why do we see a dearth of CISOs listed in executive leadership? Is this just a factor of company rep...

Mar 07, 202433 min

What Is Your SOC's Single Search of Truth?

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Steve Zalewski . Joining us is our sponsored guest, Matt Eberhart , CEO, Query . In this episode: Isn't the whole point of a single pane of glass making sense of your data? But when these dashboards are limited to a single platform, how useful are they? Do...

Feb 29, 202431 min

When Is Data an Asset and When Is It a Liability?

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, LinkedIn . Joining me is my guest, Mario Trujillo , staff attorney, Electronic Frontier Foundation . In this episode: Data is the life blood of an organization but what happens when you collect too much? Do you put ri...

Feb 22, 202435 min

Tracking Anomalous Behaviors of Legitimate Identities

All links and images for this episode can be found on CISO Series . The Verizon DBIR found that about half of all breaches involved legitimate credentials. It’s a huge attack surface that we’re only starting to get a handle of. Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Steve Zalewski . Joining me is our guest, Adam Koblentz , field CTO, Reveal Security . In this e...

Feb 15, 202434 min

Why Do Cybersecurity Startups Fail?

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, LinkedIn . Joining me is our guest, Mike Levin , deputy CISO, 3M . In this episode: Why do security startups fail? All startups are an inherently risky proposition, but what are the specific challenges for startups in...

Feb 08, 202432 min

Is "Compliance Doesn't Equal Security" a Pointless Argument?

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, LinkedIn . Joining me is our guest, Derek Fisher , Executive director of product security, JPMorgan . In this episode: A security program shouldn't stop at compliance, but that doesn't mean we should undervalue it, ri...

Feb 01, 202434 min

CISOs Responsibilities Before and After an M&A

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, LinkedIn . Joining me is our guest, Alexandra Landegger , Executive Director and CISO, Collins Aerospace . In this episode: Why do mergers and acquisitions always present challenges to an organization? When it comes t...

Jan 25, 202431 min

Use Red Teaming To Build, Not Validate, Your Security Program

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Steve Zalewski . Joining us is our sponsored guest, Richard Ford , CTO, Praetorian . In this episode: When did we all agree that red teaming was about validating security? Does it seem like increasingly red teaming is a catch all term for a whole lot of te...

Jan 18, 202432 min

The Do's and Don'ts of Approaching CISOs

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Steve Zalewski . Joining us is our guest, Adam Glick , CISO, PSG . In this episode: Vendors need to reach out to CISOs, but what does a successful approach look like? Do vendors often spray and pray with outreach, rather than doing a bare minimum of resear...

Jan 11, 202432 min

Doing Third Party Risk Management Right

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, LinkedIn . Joining me is our guest, Erik Decker , CISO, Intermountain Health . In this episode: Why are we all struggling trying to manage third-party risk? Why do the hated questionnaires seem like compliance checkbo...

Jan 04, 202431 min

Warning Signs You're About To Be Attacked

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Steve Zalewski . Joining me is our sponsored guest, Trevor Hilligoss, senior director of security research, SpyCloud. In this episode: What are the things that raise red flags that you're about to experience an attack? What signals set off your Spidey sens...

Dec 14, 202333 min

Do We Have to Fix ALL the Critical Vulnerabilities?

All links and images for this episode can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark ( @dspark ), the producer of CISO Series , and Geoff Belknap ( @geoffbelknap ), CISO, LinkedIn . Joining me is our guest, David Christensen , VP, CISO, PlanSource . In this episode: How do you actually focus your patching efforts on the vulnerabilities that are seen as universally holding the most risk...

Dec 07, 202331 min