HomePodcastDefense in Depth

Defense in Depth

DEFENSE IN DEPTH

How Much Should Salespeople Know About Their Product?

Vendors want to sell you the product they have. Their approach frequently feels more like “treating symptoms” rather than diagnosing the root causes. Check out...

Why Are We Still Struggling to Fix Application Security?

Why does AppSec feel like it's being left behind in cybersecurity? We have a lot of tooling, but it remains labor-intensive and unable to...

What Can Someone with No Experience Do in Cybersecurity?

There's often skepticism about what those new to cybersecurity can do when they enter the field. But are we creating far too many unnecessary...

Are New Gartner-Created Categories/Acronyms Helping or Hurting the Cybersecurity Industry?

It seems like cybersecurity is content to suffer death by a thousand Gartner quadrants. Why do we insist on complicating an industry that's begging...

Can AI improve Third-Party Risk Management (TPRM)

Did you know AI can fill out your security questionnaire for you? Well, if you didn',t you've missed all cybersecurity marketing in the past...

Cybersecurity Is NOT an Entry-Level Position

We often wonder why there is a lack of entry-level jobs in cybersecurity. But does that job category even apply to the field? Is...

Hey Vendors, What Problem Is Your Product Solving?

Too often, vendors focus on new features and capabilities, which miss the ultimate point of why they are selling in the first place. CISOs...

We’ve Been Fooled. There Is No Talent Shortage.

We've never had a cybersecurity talent shortage. Turns out we're being sold that story from certification vendors and companies not wanting to pay for...

Is There an Increasing Consolidation of Vendors in the SOC?

We've seen a wave of attempts at platform consolidation across the security operations center. But will the unique challenges of the SOC ultimately favor...

Are CISOs Struggling to Get Respect?

Are we headed for a mass CISO exodus? Organizations may have budget for cybersecurity, but without a committment to process, will it leave CISOs...

Is Platformization Vs Best-of-Breed a False Dichotomy?

When it comes to buying cybersecurity solutions, we’re often told the choice comes down to buying the best single tool available or buying into...

Protecting Your Backups from Ransomware

For the past few years, the focus of cybersecurity has increasingly been shifting to resilience. Core to a resilience program are backups... a safety...

Can a Security Program Ever Reach Maintenance Mode?

CISOs like to think of their job as managing risk. But once you get risk to an acceptable level, when do you start prioritizing...

The Hardest Problems in Security Aren’t “Security Problems”

Security faces many problems. Asset inventory, patching automation, config management, and device administration are all perennial challenges. But how many of them are related...

If and When Should a CISO Have a Long Term Security Plan?

How does a CISO approach strategy as they become more comfortable in their role? Is a long-term strategy even possible for a new CISO? Check...