PodcastsCarreraCISO Tradecraft®

CISO Tradecraft®

G Mark Hardy & Ross Young
CISO Tradecraft®
Último episodio

542 episodios

  • CISO Tradecraft®

    #289 - What's the Best Career Move After Being a CISO? (with Gary Hayslip)

    22/06/2026 | 43 min
    On this episode of CISO Tradecraft, host G Mark Hardy talks with Gary Hayslip about cybersecurity career growth beyond the traditional CISO “apex,” drawing on Hayslip’s 25+ years across military service, US Navy civil service, the City of San Diego as its first CISO, Webroot (CISO/CIO), SoftBank (including cyber and physical security), and most recently a field CISO role before being laid off. They discuss how the CISO role is evolving into merged executive positions (technology, risk, and AI), why continuous learning is essential as security changes rapidly, and why humans remain accountable even as AI reshapes teams. Hayslip outlines alternative paths like field CISO, data center security leadership, and VC/PE operating partner roles, and shares practical ways organizations used AI to speed legal review and automate security reporting while highlighting cost, risk, and workforce concerns.
  • CISO Tradecraft®

    #288 - How to Break Into Cybersecurity Through GRC (with Steve McMichael)

    15/06/2026 | 39 min
    In this CISO Tradecraft episode, host G Mark Hardy interviews Steve McMichael, author of "How to Break into GRC: Mindset, Methods, and Skills," about entering cybersecurity through governance, risk, and compliance. McMichael shares his transition from accounting and explains GRC’s role as decision support and the interface between business and technical teams, breaking down governance, risk management, and compliance (including audits and third-party/supply-chain assurance). They discuss misconceptions that GRC is “just paperwork,” barriers like imposter syndrome, and strategies such as building T-shaped skills, targeting about 20% technical depth across domains, and developing credibility through a deep specialty. McMichael also describes an immersion mindset driven by emotional engagement, and showcases an open-source NIST Cybersecurity Framework Profile Assessment Database project on GitHub to help newcomers build skills and portfolio contributions.
  • CISO Tradecraft®

    #287 - Cybersecurity Insights You'll Want to Hear (with Michael Hammer)

    08/06/2026 | 45 min
    Want to move from "security expert" to "trusted business leader"?
    Join G. Mark Hardy and Michael Hammer. The mind behind the core of DMARC, for 40 years of hard-won wisdom on navigating the CISO role, This episode is a masterclass in evolving from a technical gatekeeper to a strategic influencer who changes the environment,.
    Inside this episode:
    Modern Email Security: Why DMARC and SPF aren't "set and forget" tools and how to stop "cousin domain" attacks,.
    The 30-Minute Audit: Use the "Turn the Rocks Over" method to vet any vendor’s security posture in minutes.
    Risk vs. Ownership: Why you must ensure the executive team makes informed risk decisions, and why you should get them in writing.
    The AI Storm: How Mythos AI is accelerating the disclosure of years of hidden code vulnerabilities,.
    Stop being a "compliance tax" and start protecting revenue. Watch now to learn how to build a true security culture
  • CISO Tradecraft®

    #286 - AI-Native Security (with Nishant Doshi & Saro Subbiah)

    01/06/2026 | 45 min
    What if your next breach isn't caused by a human... but by an AI agent acting exactly as instructed?
    Cyberhaven's CEO (Nishant Doshi) and SVP of Engineering (Saro Subbiah) reveal why AI is a true zero-to-one shift, why every employee is building agents, and why traditional security controls are struggling to keep up with machine-speed workflows.
    The most interesting question for CISOs isn't whether AI will be adopted, it's which security control breaks first when thousands of human-plus-agent workflows start operating across your enterprise?
    Watch the episode and weigh in: What do you believe will be the first major failure point of enterprise AI adoption, identity, code review, third-party dependencies, data security, audit trails, or something else entirely?

    Big thanks to our Sponsor Cyberhaven -
    https://www.cyberhaven.com/product
  • CISO Tradecraft®

    #285 - Passwordless Authentication (with Nishant Kaushik)

    25/05/2026 | 42 min
    In this discussion, G. Mark Hardy and Nishant Kaushik explore the necessity of moving beyond traditional passwords, which they define as the original sin of cybersecurity due to their vulnerability to credential stuffing and phishing attacks. Kaushik explains that the FIDO Alliance promotes a passwordless future by replacing shared secrets with asymmetric cryptography, utilizing private keys stored on smartphones or hardware tokens like YubiKeys to ensure phishing-resistant authentication. The conversation highlights that identity is the new perimeter, shifting the focus from human-memorized codes to biometric verification and device-bound passkeys that verify user presence. Ultimately, the experts warn that a secure transition must include robust account recovery flows, as failing to secure the "back door" renders even the most advanced cryptographic-based authentication vulnerable to exploitation.
    FIDO Alliance - https://fidoalliance.org/
Más podcasts de Carrera
Acerca de CISO Tradecraft®
You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level. © Copyright 2025, National Security Corporation. All Rights Reserved
Sitio web del podcast

Escucha CISO Tradecraft®, CUENTOS y muchos más podcasts de todo el mundo con la aplicación de radio.net

Descarga la app gratuita: radio.net

  • Añadir radios y podcasts a favoritos
  • Transmisión por Wi-Fi y Bluetooth
  • Carplay & Android Auto compatible
  • Muchas otras funciones de la app