Saltar al contenido
PodcastsCarreraCISO Tradecraft®

CISO Tradecraft®

G Mark Hardy & Ross Young
CISO Tradecraft®
Último episodio

546 episodios

  • CISO Tradecraft®

    Legal Developments Every CISO Needs to Know with Larry Dietz - #293

    20/07/2026 | 41 min
    Three major legal changes. One question every CISO should be asking: Is your cybersecurity program ready?
    Congress let a key FISA surveillance authority expire. The Supreme Court raised the bar on geofence warrants. The Department of Defense paused mandatory CMMC Level 2 certifications.
    At first glance, these seem like unrelated legal headlines. In reality, they all point to the same challenge: cybersecurity leaders must understand how changing laws affect data access, privacy, compliance, and personal liability.
    In this episode of CISO Tradecraft, host G. Mark Hardy sits down with attorney and cybersecurity expert Larry Dietz to break down what these legal developments actually mean for CISOs, not from a political perspective, but from a practical leadership perspective.
    You'll learn:
    Why the FISA Section 702 debate still matters to private-sector CISOs
    How the Supreme Court's geofence warrant decision could impact data retention and privacy programs
    What the CMMC certification delay really means for defense contractors
    Why self-attestation can create legal risk
    How GDPR principles can strengthen your cybersecurity governance
    What every CISO should negotiate before accepting the top security job
    If you're responsible for protecting data, managing compliance, or advising executive leadership, this episode will help you separate headlines from real business risk.
    Subscribe for weekly insights that help cybersecurity leaders become more effective.
  • CISO Tradecraft®

    The Business Risk Playbook CISOs Use to Win - #292

    13/07/2026 | 41 min
    What separates great CISOs from everyone else? It isn't knowing more about CVEs, ransomware, or the latest security tools. It's understanding the business. In this episode of CISO Tradecraft, Ross Young and G Mark Hardy reveal why many cybersecurity leaders spend too much time protecting systems and not enough time protecting the capabilities that generate revenue, keep operations running, and create shareholder value.

    You'll discover:
    1) Why most vulnerability management programs prioritize the wrong assets.
    2) The six business capabilities every CISO should understand before making security decisions.
    3) How executive leaders evaluate cyber risk differently than security teams.
    4) A practical framework for aligning cybersecurity investments with business priorities.
    5) Why traditional third-party risk questionnaires often fail—and the questions that actually predict ransomware risk.
    6) Lessons learned from real-world breaches, mergers & acquisitions, business resilience, and executive decision making. Free Resources Mentioned

    • Ransomware Risk Assessment Questionnaire - https://drive.google.com/file/d/1L4spXwrB7nFgdSP5at2uJfFKvG_7ppmz/
    • Mission-Critical Business Capability Framework - https://docs.google.com/presentation/d/1zHjxcJXvAkJNQKXCVbVoR7yzexD3KKEu
  • CISO Tradecraft®

    The CISO Mind Map Has Evolved for the AI Era - #291

    06/07/2026 | 41 min
    How has the role of the CISO changed over the last 15 years? In this episode of CISO Tradecraft, G. Mark Hardy interviews Rafeeq Rehman, creator of the CISO Mind Map, to discuss its latest update and the biggest challenges facing cybersecurity leaders today.
    You'll learn:
    Why the CISO Mind Map was updated after 15 years
    How AI security is reshaping cybersecurity leadership
    Why the remote work category was removed
    How a RACI matrix helps CISOs delegate while staying accountable
    Why consolidating security tools reduces complexity and risk How to support your team's mental health in a high-stress industry
    What tomorrow's cybersecurity leaders need to succeed
    Whether you're an aspiring CISO or an experienced security executive, this episode provides practical insights to help you lead more effectively in the AI era.
    Link to the Mind Map - https://rafeeqrehman.com/2026/04/11/ciso-mindmap-2026-what-do-infosec-professionals-really-do/
  • CISO Tradecraft®

    Harvest Now, Decrypt Later (with Marcus Sachs) - #290

    29/06/2026 | 41 min
    Nation-state adversaries are vacuuming up encrypted traffic today, waiting for quantum computers to decrypt it tomorrow. This attack strategy, "Harvest Now, Decrypt Later," isn't theoretical. It's happening right now.
    G Mark Hardy sits down with Marcus Sachs (former White House cyber advisor, CSO of NERC, now SVP and Chief Engineer at CIS) to break down two executive orders just signed by the White House on post-quantum cryptography and what every security leader needs to do before the clock runs out.
    What you'll learn:
    Why TLS, VPNs, and PKI are your most urgent exposure
    The Harvest Now, Decrypt Later threat model and what it means for your data retention policies
    How to build a Cryptographic Bill of Materials (CBOM)
    What cryptographic agility means and why hard-coded crypto is a ticking time bomb
    Lessons from Y2K that apply directly to the quantum migration
    You can't name a date certain. But your adversaries are already running the clock.
    Links, NIST resources, and both executive orders in the show notes.
    https://www.nist.gov/cybersecurity-and-privacy/what-post-quantum-cryptography
    https://www.nist.gov/pqc
  • CISO Tradecraft®

    #289 - What's the Best Career Move After Being a CISO? (with Gary Hayslip)

    22/06/2026 | 43 min
    On this episode of CISO Tradecraft, host G Mark Hardy talks with Gary Hayslip about cybersecurity career growth beyond the traditional CISO “apex,” drawing on Hayslip’s 25+ years across military service, US Navy civil service, the City of San Diego as its first CISO, Webroot (CISO/CIO), SoftBank (including cyber and physical security), and most recently a field CISO role before being laid off. They discuss how the CISO role is evolving into merged executive positions (technology, risk, and AI), why continuous learning is essential as security changes rapidly, and why humans remain accountable even as AI reshapes teams. Hayslip outlines alternative paths like field CISO, data center security leadership, and VC/PE operating partner roles, and shares practical ways organizations used AI to speed legal review and automate security reporting while highlighting cost, risk, and workforce concerns.
Más podcasts de Carrera
Acerca de CISO Tradecraft®
You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level. © Copyright 2025, National Security Corporation. All Rights Reserved
Sitio web del podcast

Escucha CISO Tradecraft®, 30 Minutes to President's Club | No-Nonsense Sales y muchos más podcasts de todo el mundo con la aplicación de radio.net

Descarga la app gratuita: radio.net

  • Añadir radios y podcasts a favoritos
  • Transmisión por Wi-Fi y Bluetooth
  • Carplay & Android Auto compatible
  • Muchas otras funciones de la app