HomePodcastDefense in Depth

Defense in Depth

DEFENSE IN DEPTH

Do We Want CISOs Dictating How Salespeople Should Engage?

Sales is a tough job in cybersecurity. But does that make it okay to bombard a CISO for a meeting? Check out this post by...

Is AI Benefiting Attackers or Defenders?

We've been mired in endless discussions on how Adversaries and Defenders are (or could be) taking advantage of AI. Does one side have the...

CISOs DO Own the Risk

CISOs often feel excluded from company leadership. But do they need to step up and own risk to do so? Check out this post for...

How Can We Fix Alert Fatigue?

Useful alerts are critical in cybersecurity. But getting inundated with useless alerts wastes resources and our attention. How do we build out an alerting...

Vulnerability Management ≠ Vulnerability Discovery

Why have we conflated vulnerability discovery with vulnerability management? There are lots of tools that classify what's out there, but they don't help you...

Are Security Awareness Training Platforms Effective?

Security awareness is a key part of any security program. So why are we so skeptical of security awareness programs? Check out this post for...

The Argument For More Cybersecurity Startups

What is success and failure for a cybersecurity startup? The failure of a cybersecurity startup often looks like success from the outside, with most...

How Are New SEC Rules Impacting CISOs?

We're seeing increasing regulations and legal responsibilities applying to CISOs. But are CISOs set up to succeed in meeting these within their organizations? And...

Managing the Risk of GenAI Tools

We know new generative AI tools come with risk. What are you doing NOW to manage those? Check out this post for the discussion that...

Defending Against What Criminals Know About You

Are we ready to shift left on identity? What more do we need to know about identities before they enter our environment? Check out this...

Will We Ever Go Back From WFH?

We're seeing increasing evidence that no in-office perks are enough to satisfy employees into returning to the office full-time. If hybrid work is the...

The Lurking Dangers of Neglected Security Tools

Should we look at money lost from deteriorating security products the same way we look at money lost to threat actors? If so, we...

When You Just Can’t Take It Anymore in Cyber

What are the factors that lead to burnout in cybersecurity? And is the industry getting more stressful or are we finally opening up about...

Is It Possible to Inject Integrity Into AI?

When it comes to generative AI systems, often we're concerned about the quality and reliability of the output. But do we risk losing sight...

Are Phishing Tests Helping or Hurting Our Security Program?

Are we missing the point with phishing tests? We know attackers will just craft better messages to get clicks. So how can we make...