The New CISO - podcast cover

The New CISO

Steve Moorewww.exabeam.com
The New CISO is hosted by Exabeam Chief Security Strategist, Steve Moore. A former IT security leader himself, Steve sits down with Chief Information Security Officers to get their take on cybersecurity trends, what it takes to lead security teams and how things are changing in today’s world.
Last refreshed:
Follow this podcast in the Metacast mobile app to refresh it and see new episodes.
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

How Do Leaders Cultivate Diversity of Thought

Artie Wilkowsky, CISO for Dish Network, joins us on this episode to speak about specialization, leadership skills, and the qualities he looks for in new hires. Artie’s Background Artie has been working at Dish for over two years, helping with all their lines of business, such as Sling, Contact, and Wireless. Before that he bounced between consulting and industry, working in financial services and aerospace. Specialization vs. Generalization In thinking about advice for his younger self, Artie wo...

Jan 21, 202151 minSeason 1Ep. 41

Balance Budget and Tools by Rationalizing Your Security Stack

Gorka Sadowski, the CSO of Exabeam, joins us on this episode to speak about his decades of experience in cybersecurity and what he’s learned about acquiring new technology. Gorka’s Journey Although Gorka became Chief Strategy Officer for Exabeam only three months ago, he has over 30 years of experience in cybersecurity. Gorka has learned many valuable lessons along the way, especially during his time at Gartner, the global IT service management company. Each year, Gorka spoke to over 600-700 cli...

Jan 07, 202146 minSeason 1Ep. 40

The Moments After a Major Breach

On today’s episode, David Damato, the CISO at Gemini Trust Company, joins us to speak about what occurs within organizations during and after a breach—and what should happen for the best outcome. He emphasizes communication, confidence, and clarity. David’s Journey David works for Gemini, one of the few regulated crypto currency exchanges out there. It is regulated by the New York Department of Financial Services, along with other entities. They must demonstrate that they’re a legitimate organiz...

Dec 23, 202047 minSeason 1Ep. 39

Building a Student-Run SOC to Meet Threats Head-On

On today’s episode, Aaron Baillio, the CISO of the University of Oklahoma, joins us to speak about his transition from the Department of Defense to higher education, how he managed merging teams, and how incorporating students into his SOC has benefitted everyone. The Switch from DOD to Education Before Aaron worked for the University of Oklahoma, he worked for the Department of Defense for 11 years. He reflects on how the DOD is primarily concerned about keeping secrets, whereas The higher educ...

Dec 10, 20201 hr 3 minSeason 1Ep. 38

2021 Cybersecurity Trends

On today’s special episode of the New CISO podcast, Steve Moore chats with Deneen DeFiore of United Airlines, Colin Anderson of Levi Strauss & Co. and Charlie McNerney of Expedia on what it’s been like as a CISO during the pandemic. COVID and the Airline Industry Deneen begins by discussing how she became the CISO for United Airlines right as COVID hit. When the pandemic reached the US, there was a lot of fear that the airline would not make it. Because of this additional stress, Deneen focu...

Nov 26, 202059 minSeason 1Ep. 37

Are Hiring Policies Driving the Cybersecurity Skills Shortage?

On today’s episode, Steve Marshall, the CISO of the UK Group for Byte Software, discusses how he moved from biophysics to cyber security, how security impacts business decisions, and why he thinks the hiring process of the industry is overlooking talent for certifications. Steve’s Journey Steve originally studied physiology and was on his way to receiving his PhD when the IT world called to him. He ended up not completely his degree to work in IT and become the head of the department, and eventu...

Nov 12, 202051 minSeason 1Ep. 36

Translating Your Military Experience of Operationalizing Security into the Private Sector

On today’s episode, Jeff Schilling, the CISO for Teleperformance, joins us today to discuss the transition from a security career in the military to the private sector, the importance of relationships, and security in relation to the Cloud. Transition from the Army to Civilian Life Jeff recounts his career in CISO, first discussing Teleperformance, which he joined this year. He then dives into the 24 years he spent in the military, which ended with his retirement as a Colonel in 2012 from US Arm...

Oct 29, 202053 minSeason 1Ep. 35

Culture Eats…Security for Breakfast

On today’s episode, George Finney, the CISO of Southern Methodist University, joins us to discuss how cybersecurity is a team sport that depends on openness and collaboration, and examine how culture can directly impact the likelihood of future breach. How a Law Degree Helped George George Finney is an accomplished CISO with a more unique background: he has a JD. While it’s becoming more common for CISOs to get an MBA, it’s rare that they would have a law degree. He attended night law school whi...

Oct 15, 202047 minSeason 1Ep. 34

Managing Risk While Building Trust in a Post - Breach Environment

On today’s episode, Charlie McNerney discusses shared responsibility in cybersecurity, the idea of trust, and how diagnosing a problem before treating it has aided him in his career. Early Retirement and Intellectual Income After working 25 years at Microsoft, Charlie retired early. Six months later—after getting a boat and a dog—he found himself bored and seeking, what he calls, an “intellectual income experience.” After a phone call from a friend, Charlie ended up consulting for Expedia Group,...

Oct 01, 202055 minSeason 1Ep. 33

Lessons Learned from the “First CISO” Part 2

On today’s episode, we continue our conversation with Steve Katz, the first CISO, and discuss the importance of understanding yourself, your role, and the company for which you work. Marketing Yourself Within the Company One of the things that Steve stresses is that you need to be able to market yourself and the role of CISO to the rest of the company. It’s only in your best interest to know how to articulate why cybersecurity matters and how it impacts the business. In order to do so, you must ...

Sep 17, 202039 minSeason 1Ep. 32

Lessons Learned from the “First CISO” Part 1

Early Days of Security at Morgan Steve first began working in cybersecurity at JPMorgan, then known as Morgan Guarantee. He recounts the attitude towards CISOs in the 1980s, where many people didn’t really have a concept of cyber security or what it looks like. When Steve started, he had to change access rules and work against the resistance to PCs and Apple technology in banks. Listen on to hear his stories and how he overcame skepticism towards cybersecurity. Building an Active Community One o...

Sep 03, 202039 minSeason 1Ep. 31

The Benefits of Finding a Security Vendor Who Can Act as a Trusted Advisor

Improving the Sales Process In this episode, we discuss how and why it’s so difficult for a security team leader to discover new trends in technologies in a safe and effective way. Damien points out that it can be challenging to discern who and what to rely on when broaching new systems. Listen to the episode to hear more about how to find the right balance of someone who understands the company and the importance of building a long term, trusted relationship. Advice for the New Salesperson One ...

Aug 20, 20201 hr 3 minSeason 1Ep. 30

Why the “Shiny New Thing” in Cybersecurity Isn’t Necessarily the Best Solution

In this episode of the Exabeam Podcast, the host, Steve, and guest Chris Ard, discuss the more human aspects of the CISO role, effective leadership, and how complacency can be a dangerous quality. Work-Life Balance The first topic we covered was finding a work-life balance that benefits you and your family. Chris spent twenty years working for Microsoft, traveling all over to companies with major security breaches and helping them control the situation. Although he learned a lot and loved his jo...

Aug 06, 202049 minSeason 1Ep. 29

Making the Leap from Engineering to Cybersecurity Leadership

In this episode of The New CISO Podcast, the host, Steve, and guest David Rule of HarbourVest, discuss the skills he learned to transition from engineering to executive management, the evolution of leadership styles, and better ways to prepare for crisis management. Transition from Engineer to Executive Manager The first topic we covered was David’s transition from being on the tech side of security, to assuming a CISO position. We discuss how this change may be more challenging than originally ...

Jul 23, 202044 minSeason 1Ep. 28

Is Our Understanding of who Owns Risk Driving CISOs to the Edge?

In this episode of The New CISO Podcast, the host Steve Moore, and guest Gary Hayslip discuss the difficulties veterans face when transitioning to the business world. They also converse on how to remedy security failings, and how risk ownership mentally and physically impacts CISOs. A Challenging Transition for Military Personnel After serving in the military for however many years, enlisted personnel receive one class on how to transition to civilian life. While the class teaches how to format ...

Jul 09, 202048 minSeason 1Ep. 27

The State of the SOC in 2020

The American vs. European view on Insurance In first reviewing the report, we were struck by how Europe leads the rest of the globe in insurance to manage risk compared to the US. While the adoption rate of insurance is slowly growing in American companies, their European counterparts take precedence. This could be because European teams have a better understanding of how to use certain types of insurance, or that the European insurance markets and carriers better address cybersecurity risks tha...

Jun 25, 202054 minSeason 1Ep. 26

Determining Risk Tolerance for a 100-Million-User per Month Organization

Tune in as Steve Moore talks with Christopher Hymes, the CISO of Riot Games, about acceptable risk and the parallels between anti-cheat teams and threat hunting. Security Within The Gaming World The video game market is massive, there are a ton of games and a ton of gamers out there. Like any large industry, the gaming industry is not immune from security threats. Games are fun because they are competitive, you have to build the gaming skills over time. This opens up an entire market for cheatin...

Jun 04, 202049 minSeason 1Ep. 25

Getting on With the Business of Security, by Building Trust

Career Transitioning After Decades With Another Organization Being with the same organization for a long period of time is a wonderful achievement, but when you’re ready for a change of scenery, the transition can be tough after such a long stint with one organization. Being able to set up into your new role with fresh eyes and ears to really listen and get to know your new team can quickly build that working dynamic. If the industry is different from the previous organization, that adds another...

May 21, 202041 minSeason 1Ep. 24

Recovering from a 'Bad CISO'

Advice To A Younger Self A core truth to being successful is always delivering more than the organization expects. Going above and beyond to find out what is most important to your customers is key. Make the customers reality your reality and work from that viewpoint. Figure out their definition of value and find your place in that value, then fuse those two points together. The Previous CISO Failed To Deliver A lot of times a bad CISO isn’t something that happens in a purposeful manner. The org...

May 07, 202049 minSeason 1Ep. 23

How Do You Measure the Success of Your Cybersecurity Program?

Taking The Jump From Consulting & Advice To A Younger Self With consulting you have the opportunity to work with multiple large companies, which can be an attractive aspect of the job. Working with multiple companies on that scale can introduce you to the latest technology and how it works differently for different companies. That being said, if you want to build a team from the ground up a transition from consulting might be best for you. Also if you’re looking to partner, or gain any owner...

Apr 23, 202034 minSeason 1Ep. 22

How Emotional Intelligence Fortifies Capability In the Midst of A Crisis

Building A Relationship With Other Teams The sooner these relationships can be built, the better. Meeting top executives and other team leads during a crisis is less than ideal. Get to know the people that are closer to the consumer, the writers, the social media managers, the sooner this relationship is established the better the partnership is when you need to come together in a crisis. Building those relationships now build trust within the company as a whole. Where To Begin? Every company is...

Apr 09, 202048 minSeason 1Ep. 21

Strategies for Securing a Remote Workforce

Building Up To A Position Of Power Holding the dual position of CTO/CISO needs to come with a lot of experience and drive. Being able to build the security organization around the needs of the company led to being both the Chief Technology Officer as well as Chief Information Security Officer. Noticing what was interfering with the safety of the company through passive observation has directly played into both roles. Doing research, having conversations, and interacting with other people are all...

Mar 26, 202048 minSeason 1Ep. 20

No as a Service: Why Security Can Stifle Innovation and How to Prevent It

Transitioning Into The CISO Role Learning to balance the executive role with the tactical needs of the team can be tricky to balance. Being able to see to the larger picture within both roles can keep you on track and relevant within both places. Remember the roles you’ve had in the past and draw from those experiences and knowledge. Audits are typically not something anyone wants to have on their plate, but there are values in the audits. Audits not only bring an extra set of eyes to your team,...

Mar 12, 202045 minSeason 1Ep. 19

Losing Your Job as a CISO: Does the Cybersecurity Skills Shortage Extend to Executives?

The Day You Lose Your Job Losing your job to many can come as a complete shock, maybe even more so when you’re in a position of power such as an executive role. There are many extra steps when leaving a security executive position, sometimes you have to hand over your phone, computer, tablets for security purposes, and if you used this for personal use as well, you could lose a lot of valuable files and information. Sometimes you don’t even get a clear picture of why you are being let go, and th...

Feb 27, 202044 minSeason 1Ep. 18

Your First 90 Days As A New CISO

Initial Worries & New Challenges Going from consulting into a leadership position requires you to take on a new level of responsibility. You take that leap of having more permanence in the position but also now having to lead a team of other security professionals. Olivia also was in the unique position of not only being a new CISO but also the first CISO at MailChimp. This unique position came with high expectations but also a rewarding sense of accomplishment when goals are being reached. ...

Feb 13, 202050 minSeason 1Ep. 17

From the 'Basement' to the Board: Giving Cybersecurity Teams Greater Visibility

Advice To A Younger Self, Before Becoming A CISO Perfectionism can hinder the natural learning experience. As someone fresh in their career it can be hard to not want to be perfect, there are expectations to be met. Yet making mistakes and learning from them is real job experience. Don’t be afraid to take risks and fail, you’ll learn from your mistakes. Being new in your career can feel isolating, vulnerable, and flat out scary. It is okay to make mistakes, just learn from them Gender In The Wor...

Jan 31, 202046 minSeason 1Ep. 16

Lessons in Leadership: Taking a Step back and Learning to Trust the Experts on Your Team.mp3

Transitioning Into CISO And The Initial Challenges Becoming the head of any department, and having all that responsibility on you can be very intimidating at first. Going from more behind the scenes to front and center can be uncomfortable, but reflect back on all your experience and let that guide your decision-making. Delegation is important in leadership roles, so get the team together and put your minds together to build a great security team. Identify the top priorities for your position, f...

Jan 17, 202051 minSeason 1Ep. 15

Why 3rd Party Security Testing is the New Password Rotation

Identifying Burnout In The Workplace Burnout is a common occurrence in any industry, but especially among those looking to carve out their place in the industry. No one works well when they aren’t at their best, identifying burnout early on can stop it in its tracks. If you’re noticing someone is acting out of character or being short, they may be experiencing burnout. Another tell can be the hours you’re seeing someone put in, no one should be up at midnight still working. Advice To A Younger Y...

Dec 30, 201950 minSeason 1Ep. 14

Unique Challenges, but More Opportunities for Women in Cybersecurity

Marketing In Relation To Security Marketing is all about getting a certain message to the right audience. A background in this field can be a great way to transition into other positions including the CISO. Being able to take a look at the bigger picture and then funnel that picture down to solve the problem at hand can be aided with a marketing approach. Advice To Those Just Starting Out Being new in an industry can be isolating by itself alone, but being female in a male dominated industry can...

Dec 13, 201947 minSeason 1Ep. 13

2020 Cyber Security Trends

The Slow Evolution Of The CISO The role of the CISO is changing but maybe not at the preferable speed. The role has been changing throughout the existence of the CISO from a small technical role to an IT position, to a role that is more demanding than ever. It is becoming a much more executive role than in the past. Connecting The Changing CISO Position To The Business Needs To understand the business needs, as the CISO the business needs to understand you, and your role with the company. Paint ...

Nov 26, 201953 minSeason 1Ep. 12
For the best experience, listen in Metacast app for iOS or Android