556 episodios
- Should you get a PhD in Cybersecurity?
In this episode of CISO Tradecraft, G. Mark Hardy sits down with Dr. Char Sample at the COSAC security conference in Ireland to unpack what it REALLY takes to earn a doctorate in cybersecurity.
From her early work on the Gauntlet firewall to cybersecurity research at the Army Research Lab, INL, and Marshall University, Dr. Sample shares hard-earned lessons on research, funding, doctoral programs, and surviving the PhD journey.
They also explore:
Why a PhD can matter for cybersecurity research funding
What makes a strong cybersecurity research problem
How long a doctorate can take
Research methods, proposals, and defending your work
Remote vs. residency programs
AI, hallucinated citations, and research reproducibility
Why cybersecurity needs more focus on building securely, not just breaking things
If you're considering an advanced degree or want to understand where cybersecurity research is headed, this episode is for you.
🎧 Subscribe to CISO Tradecraft for more cybersecurity leadership insights. - In this episode, we reveal the biggest security awareness mistakes and the creative ways to make cybersecurity training actually fun in 2026.
From AI-powered phishing and token theft to stronger MFA and gamified training, There are ideas every security leader should steal.
Watch now and level up your security awareness game! - Most CISOs spend years learning cybersecurity.
Almost nobody teaches them how to build a culture people actually want to be part of.
In this episode of CISO Tradecraft, G. Mark Hardy and Ross Young break down the leadership lessons that separate average security organizations from world-class ones.
You’ll learn how to:
Build a security team people WANT to join
Develop your employees into future CISOs
Reward behavior that actually changes culture
Communicate like an executive
Spot when your company may NEVER promote you to CISO
Prevent burnout before your best people leave
Build trust across the business
Create a culture of excellence, accountability, and curiosity
Ross also shares how he turned phishing awareness into a company competition, complete with trophies, CEO recognition, and brisket parties.
Because great cybersecurity leadership isn't just about stopping hackers.
It's about building an organization where great people can do their best work.
What’s the ONE leadership rule every CISO should follow?
Subscribe to CISO Tradecraft for practical lessons on cybersecurity leadership, strategy, risk, and becoming a more effective CISO.
Template for Command Philosophy: https://www.gmarkhardy.com/Navy_Articles/NRA-0306%20Template%20for%20a%20Command%20Philosophy.pdf - The biggest threat to a CISO might not be ransomware, it might be burnout. In this episode, G. Mark Hardy brings on We Hack Health to reveal why brilliant security leaders are sacrificing their health, how accountability can reverse the damage, and the one rule every CISO should follow: Never miss twice. Watch this before your career costs you everything.
Link to CruiseCon
https://cruisecon.com/events/cruisecon-privacy-ai-2026/
Use code: CISOTRADECRAFT10 for a 10% discount - Claude Code Is INSANE… But Is It Safe?
AI coding just went from “autocomplete my code” to “give me the entire repository and let me run the company.”
In this episode of CISO Tradecraft, G Mark Hardy and Ross Young break down what Claude Code can actually do, and the security implications that come with it.
Claude Code can read entire codebases, create and edit multiple files, run commands, execute tests, and operate like an AI developer sitting directly inside your environment.
But there’s a catch…
Every token costs money. And every permission creates risk.
We break down:
🔥 Tokenomics — How to get dramatically more AI coding for your dollar
🔥 PRDs — Why you should use powerful models to THINK before cheaper models BUILD
🔥 Security Risks — What happens when an AI agent can execute commands and modify your environment?
🔥 AI Licenses — Individual vs. enterprise and what CISOs need to worry about
🔥 Privacy & Regulated Data — When you may need offline or open-weight models
🔥 Harnesses — The policy-driven guardrails that can move security WAY earlier in the development process
🔥 MCP — How AI agents can connect to tools, systems, and data… and why permissions become a massive security issue
🔥 Agents & Skills — Serial vs. parallel agents, prompts, context, commands, hooks, and Markdown-based skills
🔥 Threat Modeling AI — Why you need to start threat modeling the prompts AND the tools
The big question isn't:
“Can AI write code?”
It absolutely can.
The question is:
“What happens when we give AI the keys to the kingdom?”
If you're a CISO, security leader, developer, or anyone trying to understand where agentic AI coding is heading, this episode is for you.
🎙️ Subscribe to CISO Tradecraft for more unfiltered conversations about cybersecurity, AI, leadership, and the future of the CISO.
Check out the Harness that Ross is building:
https://github.com/Clear-Capabilities/agentic-security
Más podcasts de Carrera
Podcasts a la moda de Carrera
Acerca de CISO Tradecraft®
You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level. © Copyright 2025, National Security Corporation. All Rights Reserved
Sitio web del podcastEscucha CISO Tradecraft®, 30 Minutes to President's Club | No-Nonsense Sales y muchos más podcasts de todo el mundo con la aplicación de radio.net

Descarga la app gratuita: radio.net
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app
Descarga la app gratuita: radio.net
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app


CISO Tradecraft®
Escanea el código,
Descarga la app,
Escucha.
Descarga la app,
Escucha.









