Pragmatic CSO Podcast - podcast cover

Pragmatic CSO Podcast

The Pragmatic CSO podcast is a wide ranging discussion of information security topics, anchored by the 12-step Pragmatic CSO methodology to help security practitioners become more relevant in business operations.
Last refreshed:
Follow this podcast in the Metacast mobile app to refresh it and see new episodes.
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

Pragmatic CSO Podcast #23 - Picking the Right Product

This week we'll focus on the 2nd half of Step 6: Buying Security Products, which get down and dirty in picking the product. We've already engaged with a long list of potential vendors (we discussed that last week) and now it's time to figure out what will work for you. Next we do a bake-off and actually test the products under real world conditions. Then we develop our short list (based on products that can meet the need), then we get to negotiate. Get out your bat because that's what you'll be ...

Sep 25, 20082 min

Pragmatic CSO Podcast #22 - Homework for Buying Security Products

As we jump into Step 6: Buying Security Products, it makes sense to understand what kind of homework we are going to have to do prepare for the process. Remember, it's easy to buy something, it's hard to buy the right thing at the right time for the right price.So this week we discuss the first 4 steps of the Buying Security Products process I published back in 2006. The first step is to understand the business drivers for your project, then you assemble the team, then you educate YOURSELF on th...

Sep 17, 20082 min

Pragmatic CSO Podcast #21 - Grass Roots Funding

It's time to wrap up Step 5: Selling the Story. We finish the discussion by talking about how to get funding, when the budget monkeys have told you no. Basically we have to take a "grass roots funding" approach to go to the business leaders directly, make the case, and get the funding we need. It's kind of like selling cookies door to door. We have to be persistent and make the case as to why it would be a good purchase.This requires us to broaden our skills and likely move out of our comfort zo...

Aug 13, 20083 min

Pragmatic CSO Podcast #20 - The Sales Pitch

July 30, 2008 - This week we talk about the sales pitch. This is the part that most security practitioners hate. Actually having to get in front of folks and ask for money. Although if you've followed the process up to now, then you should be in great shape to put together a compelling story and to deliver that message to the senior team.In this week's episode (can you believe it's #20 already?), I go into detail about how to structure the sales pitch and what you should discuss and why. We are ...

Jul 30, 20082 min

Pragmatic CSO Podcast #19 - Resetting Expectations

This week we continue with Step 5: Selling the Story by reiterating the need to manage expectations appropriately. As you know, this is a common theme throughout the Pragmatic CSO, but when we are selling senior management on the security program, strategy, outputs, milestones, and funding requirements - now is really the last time we'll have to truly set expectations. If you screw this up now, you will not be successful. Now is the time to stand firm with your milestones and what you can (and c...

Jul 02, 20082 min

Pragmatic CSO Podcast #18 - Finding the Bags of Money

June 25, 2008 - This week we start into Step 5: Selling the Story by discussing funding scenarios. This is a technique that Pragmatic CSOs use to provide some alternatives and make the scenario we want (the likely one) a bit more tangible by providing alternatives.In the show, I discuss how to develop these scenarios using your Security Architecture Matrix and then why it's important to discuss what won't get done, as part of these funding scenarios.Running time: 6:20Intro music is Jungle and yo...

Jun 25, 20082 min

Pragmatic CSO Podcast #17 - Back to the Future

Finally we come to the end of the line on building the security business plan. It was a long time coming, but again this is the most important step in effecting long lasting change in your security organization. First I talk about defining the future state, and setting priorities relative to what you must have, should have, and is nice to have. Then it's all about setting up the migration plan, which needs to be in alignment with the timelines and milestones that we discussed last week. A lot of...

Jun 18, 20082 min

Pragmatic CSO Podcast #16 - Time and Milestones

This week we delve into the art of setting timelines and milestones within your business plan. After we discussed the importance of setting the bar (in terms of service levels), it's the timelines that really will determine your ultimate credibility with the senior team.Once you define the key timelines, it's also important to have a process to revisit the project plans and to communicate variances. You need to expect that some of the initiatives will run off the track a bit and ensure you are a...

Jun 11, 20082 min

Pragmatic CSO Podcast #15 - Setting the bar

This week we talk about service levels within the context of your security business plan. That's right, this is about setting the bar. Too high and you can't get there and you will be viewed upon as a failure in the executive wing. Too low and you may open yourself up to a breach on your watch. So we are looking for something "just right." We also need to start thinking about how to quantify some of the stuff we are doing, and now is not the time to look for innovative means of pulling security ...

May 28, 20082 min

Pragmatic CSO Podcast #14 - Architecture vs. Design

Ah the mysteries of architecture. I can remember back to my days in college at Cornell. We had a great architecture school, but those folks seemed like magicians. They weren't around too much and it seemed like they were doing cool things, we engineers just didn't understand what it was. Understanding how to build your security architecture isn't all that different. So this week, I delve into the nuances of architecture vs. design and also provide a brief description of the " Pragmatic Security ...

May 22, 20082 min

Pragmatic CSO Podcast #13 - Digging Deeper into the Business Plan

This week we are going to dig a bit deeper into the business plan and deal with the first two sections of the plan. Initially we need to POSITION our securirty organization. What are we doing and why is it important? Then we need to make our PRIORITIES very clear. What do we focus on first and why? The business plan is as much for them (meaning your senior executives and the like) as it is for you. So you need to start the plan off with a bunch of information about them, before you get back to w...

May 14, 20083 min

Pragmatic CSO Podcast #12 - Why do we need a business plan?

This week we get back into the Pragmatic CSO methodology, and jump into Section 2: Building Your Pragmatic Security Environment. The first step in S2 is Step 4 or Building Your Security Business Plan. Why do we need a business plan anyway? What's the point?All is revealed in podcast #12. Well OK, not all - but I lay the groundwork on why the business plan is probably the most important of the 12 steps and what goes into building it. Over the next 2 months or so, we'll be delving deeply into the ...

May 07, 20082 min

Pragmatic CSO Podcast #11 - The Fixer

This week I take another tangential journey to discuss a concept I call "The Fixer." You know, when a senior staffer is airlifted in to "fix" security. The Fixer knows how to get things done in your organization, and can certainly be viewed as a threat and as indicative of the fact that security is broken.How should you deal with the Fixer? Why is he (or she) there? Can you turn this into an advantage?Check out podcast #11 and find out... Running time: 6:40Intro music is Jungle and I sign off wi...

Apr 23, 20082 min

Pragmatic CSO Podcast #10 - It's So Easy

April 16 2008 - Today I go on a bit of a tirade. Basically, just coming back from RSA - I'm a bit sensitive to vendor claims vs. reality. Thus, after I've been pounded by a webcast announcement from AlertLogic for the past week about "PCI Compliance made Easy." After I cleaned the puke off my desk, I needed to rant a bit. So this week's podcast is a little different. All rant, no filler.Here is the invite, so you have some context... The event is today, so you can figure out just how "easy" secu...

Apr 16, 20082 min

Pragmatic CSO Podcast #9 - Making Deposits in the Credibility Bank

This week we wrap up our stop in Step 3: Managing Expectations by talking about the long term plan. The first step of the managing expectations presentation is all about providing the context of the program and educating the senior team about why it's important. Then next step is about triage. Based on the baseline, what are the most important things that need to be tackled RIGHT NOW. Finally, we are in a position to start accepting responsibility for the long term success of the security progra...

Mar 20, 20082 min

Pragmatic CSO Podcast #8: Triage (or saving the patient)

This week we continue our journey through Step 3: Managing Expectations and talk about how to present the "bad news," as part of your efforts to ensure the senior team knows what you are up to and why. The triage part of the discussion is also pretty important because it will indicate whether you have a snowball's chance in hell of actually making progress on the program. If you can't get agreement on the 2 or 3 things you think are most important to do TODAY - then it doesn't bode well for the ...

Mar 12, 20082 min

Pragmatic CSO Podcast #7 - Educating the Team

This week we dive into Step 3: Managing Expectations and investigate why one of the most important things a security professional can do is to give the senior team the PERCEPTION that you're in CONTROL of the situation. Reality means little, perception means everything.A couple of the topics covered include:- Why managing expectations around security is hard- How to provide context about what a security program is about- The 3 most important ideas to convincing someone you have your act together...

Mar 06, 20082 min

Pragmatic CSO Podcast #6 - Assessing the Skill Gap

This week we wrap up on Step 2: Taking the Baseline by being candid with ourselves and really understanding if we have a skills gap. This is one of the most brutal parts of being a manager, but it needs to be done.I refer to a few books from the Gallup Organization, so you can understand what may be a different way of thinking about management. First, Break All the Rules and Now, Discover Your Strengths .I don't have to manage much of anything nowadays, but these resources and philosophy were in...

Feb 27, 20082 min

Pragmatic CSO Podcast #5 - Dig (into) the Baseline

This week, we continue our journey through Step 2: Baseline Your Environment. Here are a couple of the topics covered: Finding the holes in your perimeter Looking at your applications (the most IMPORTANT one's anyway) The softer side of security: User perception and user awareness Also make sure to listen for Dr. No. He makes a special guest appearance in today's show.Time: 5:43Intro music is Jungle and I sign off with Ozzy's No More Tears. Yes, one of the classic bass lines in rock.Image credit...

Feb 13, 20082 min

Pragmatic CSO Podcast #4 - Wherefore art thou policies?

February 8, 2008: This week's show starts to delve into Step 2: Establishing the Baseline. Why you need to do this, what you are trying to achieve, and a little bit on policies (such as a monitoring policy and a communications plan).Intro music is once again "Welcome to the Jungle" and I send you on your way with Aerosmith's "Get a Grip," since that is what taking the baseline is all about.

Feb 08, 20082 min

Pragmatic CSO Podcast 3 - Getting Facetime

In this week's show I talk about getting facetime without feeling like you are banging your head against the wall. Basically a key part of Step #1 and in a broader perspective, your success as a CSO is about building relationships with the senior team and understand what is important to them. How do you do this, when they are pretty busy and don't really want to spend any time with you? I map out a 3 step process (and hopefully you only need two steps) to get on their calendar and also talk abou...

Jan 23, 20082 min

Pragmatic CSO Podcast #2 - Whack a Mole

January 16, 2008 - Today's show talks about Whack a Mole and why it's an appropriate metaphor for information security nowadays.Image source: http://www.creativepro.com/printerfriendly/story/20990.html

Jan 16, 20082 min

Pragmatic CSO Podcast #1

January 11, 2008 -Welcome to the Inaugural Pragmatic CSO Podcast. In today's show, I talk a bit about: Why I am doing a podcast (and what to expect) The 12-step Pragmatic CSO methodology Why it's tough to be a security professional nowadays A message of hope Check it out and since this is the first edition, let me know what you think. I'm definitely open to comments relative to how to make the show better.

Jan 11, 20083 min
For the best experience, listen in Metacast app for iOS or Android