HomePodcastDefense in Depth

Defense in Depth

DEFENSE IN DEPTH

Why Do Cybersecurity Startups Fail?

Why do security startups fail? All startups are an inherently risky proposition, but what are the specific challenges for startups in our industry? Check out...

Is “Compliance Doesn’t Equal Security” a Pointless Argument?

A security program shouldn't stop at compliance, but that doesn't mean we should undervalue it either. It's easy to just say compliance comes down...

CISO Responsibilities Before and After an M&A

Mergers and acquisitions always present challenges to an organization. When it comes to cybersecurity, how involved should a CISO be before AND after an...

Use Red Teaming To Build, Not Validate, Your Security Program

When did we all agree that red teaming was about validating security? It seems like increasingly red teaming is a catch all term for...

The Do’s and Don’ts of Approaching CISOs

Vendors need to reach out to CISOs, but what does a successful approach look like? Too often vendors spray and pray with outreach, rather...

Doing Third Party Risk Management Right

If third-party risk management becomes too broad, it effectively becomes worthless. But too narrow and you'll miss critical risks. So how do you strike...

Warning Signs You’re About To Be Attacked

What are the things that raise red flags that you're about to experience an attack? We know phishing is one major indicator, but what...

Do We Have to Fix ALL the Critical Vulnerabilities?

For years we've heard mantras like "patch all the things." But with limited resources, how do you actually focus your patching efforts on the...

Mitigating Generative AI Risks

As with any new technology, generative AI comes with a set of risks. So how can we address these risks to take advantage of...

Building A Cyber Strategy For Unknown Unknowns

As security professionals, we know a lot of the things we lack visibility into that can cause security issues. That alone is enough to...

Responsibly Embracing Generative AI

Businesses are walking a tightrope with generative AI. One the one hand, it's a potentially disruptive technology, and no one wants to be the...

People Are the Top Attack Vector (Not the Weakest Link)

In increasingly complex technical defenses, threat actors frequently target the human element. This makes them a top attack vectors, but are they actually the...

What’s Entry Level in Cybersecurity?

We often talk about the contradiction of seemingly entry-level security jobs requiring years of experience. But maybe that's because entry-level jobs don't actually exist. Check...

New SEC Rules for Cyber Security

The Securities and Exchange Commission issued new cyber rules. What do these new rules mean for CISOs and will they ultimately improve our cybersecurity...

The Value of RSA, Black Hat, and Mega Cyber Tradeshows

Are trade shows like RSA getting so big that there's not enough economic value for a CISO to attend? Or do these events have...