HomePodcastDefense in Depth

Defense in Depth

DEFENSE IN DEPTH

Who Is Responsible for Securing SaaS Tools?

Haven’t we already discussed at great length the cloud shared security model? We've had the cloud for a few decades. Why can't we just...

Hiring Cyber Teenagers with Criminal Records

Threat actors don’t need certifications or a degree to be good at their job. So why do we keep trying to demand those from...

What’s Working With Third-Party Risk Management?

We know third-party risk management is a pain. If nobody likes the universally agreed upon solutions like questionnaires, what are we doing that's improving...

What Triggers a CISO?

CISOs are familiar with dealing with stress, making high-stakes decisions, and operating in an industry of unknown unknowns. But there are some things that...

Information Security vs. Cybersecurity

CISO stands for Chief Information Security Officer. So why do we sometimes pigeonhole their duties under "just" cybersecurity? Check out this post for the discussion...

Should Deny By Default Be the Cornerstone of Zero Trust?

How far can we extend a deny-by-default approach as we build out our zero-trust architecture? Can that aggressive security tactic work for the business...

What Is a Field CISO?

We're increasingly seeing the industry fill up with Field CISOs. Why is the CISO out in the field? What does that role entail? Check out...

Cybersecurity Is a Communications Problem

Is cybersecurity a communication problem at its core? If communication is so critical in cybersecurity, why do we keep seeing so many failures?  Check out...

Do Companies Undergoing a Merger or Acquisition Get Targeted for Attacks?

There's a common assumption that mergers and acquisitions put organizations at more risk of cyberattacks. Is there any data to back up this well-worn...

Telling Stories with Security Metrics

We know that storytelling is a key to communicating risk to the business. How do we integrate metrics to help us tell those stories? Check...

Securing Identities in the Cloud

How are we securing identity in the cloud? Unlike on-prem, the cloud requires you to cede control to a vendor. So what can we...

How AI Is Making Data Security Possible

Have we lost sight of data security with defense in depth? Recent trends have seen a focus on applications and roles, but do we...

What Makes a Successful CISO?

Every CISO has a unique path to getting the role. But once you're there, what does it take to be effective? Check out this post...

We Want a Solution to Remediate, Not Just Detect Problems

Discovery of security issues is important, but ultimately we need them remediated. So why do so many solutions seem to stop short? Check out this...

Recruiting From the Help Desk

Working the help desk seems like a great place to get entry-level cyber security skills. So why is it so often overlooked or even...