1538132658
CISO Tradecraft®

Advertise on podcast: CISO Tradecraft®

Rating
★★★★★
4.8
from
49 reviews
Categories
Country
United States
This podcast has
280 episodes
Language
English
Explicit
No
Date created
2020/10/30
Latest episode
2026/04/20
Average duration
45 min.
Release period
8 days

Description

You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level. © Copyright 2025, National Security Corporation. All Rights Reserved

Unlock CISO Tradecraft® podcast Email contact info,
Listeners & Audience details

Email contact information

Direct podcast contact details

Listeners

Audience numbers & engagement insights

Audience details

Podcast Insights

Social media

Check CISO Tradecraft® social media presence


Podcast episodes

Check latest episodes from CISO Tradecraft® podcast


#280 - Mythos and the Future of Vulnerability Operations (with Gadi Evron)
2026/04/20
In this episode of CISO Tradecraft, host G Mark Hardy speaks with Gadi Evron about the paper “The AI Vulnerability Storm Building: A Mythos Ready Security Program,” a community-driven draft produced in days with extensive input from security leaders. Evron explains how advances in LLMs and agents are accelerating vulnerability discovery and exploitation, shrinking time-to-exploit assumptions and likely increasing the volume of real vulnerability reports and patches. They discuss separating hype from real risk, the impact of Anthropic’s Mythos and limited access via Project Glasswing, and what CISOs should do now: adopt agents to operate at machine speed, use them defensively to find issues, build “vuln ops” capabilities, secure coding agents in the enterprise, and communicate shifting risk metrics to boards. They also preview the next Unprompted conference planned for September. VulnAxis - https://vulnaxis.com/ Gadi Evron - https://www.linkedin.com/in/gadievron/ Knostic - https://www.knostic.ai/ The AI Vulnerability Storm Paper - https://labs.cloudsecurityalliance.org/mythos-ciso/ Unprompted - https://unpromptedcon.org/
#279 - AI Readiness (with JP Bourget)
2026/04/13
On CISO Tradecraft, host G Mark Hardy welcomes back JP Bourgeet to discuss what “AI readiness” means for organizations, framing it as both a data governance challenge and a change-management problem. JP defines readiness for CISOs as strong threat protection, data security/governance, and device management, with the biggest gaps typically in labeling, DLP/DSPM, and poor information architecture (e.g., commingled data in SharePoint/Drive). They cover re-architecting past and future data into role-based structures so Copilot can honor permissions and sensitivity labels, plus the value of visibility, auditability, and insider-risk alerting for file access and LLM prompts. JP also discusses agentic systems and upcoming identity challenges for AI agents, compares AI readiness to platform engineering, emphasizes use-case-driven adoption (lunch-and-learns and ROI tracking), and highlights Daniel Miessler’s personal AI infrastructure work and a future shift toward AI-driven security products. JP Bourget's Website https://www.bluecycle.net/ JP Bourget's Linkedin https://www.linkedin.com/in/jpbourget/ SaltCon- https://naclcon.com/
#278 - RSAC Takeaways: AI SOC, Agent Security, and What Cyber Marketing Gets Wrong
2026/04/07
In this CISO Tradecraft episode, G Mark Hardy, Ross Young, and Andy Ellis share RSAC insights from the vendor floor, including Andy’s effort to visit about 607 booths. They highlight dominant themes like AI SOC offerings and agentic/agent security messaging, noting that many booths used unclear marketing or even failed to describe what they do. The discussion critiques activity-based metrics like badge scans, arguing for outcome-focused goals such as awareness, qualified follow-ups, and customer-driven product feedback. They explore how marketing should create informed buyers, how startups should communicate problem, urgency, and differentiation, and how AI and “vibe coding” may pressure vendor pricing or encourage internal tool-building. The episode also covers open-source sustainability and recommends networking via both major conferences and smaller private CISO events. Take a look at these three helpful RSAC Reviews: DUHA - https://www.duha.co/reports/state-of-security-vendors-rsac-2026/ VibeCoded - https://vibecoded.vc/cooked/ Jake Epstein's RSA 2026 Startup Landscape - https://jakee.vc/rsa-2026-landscape.html
#277 - From SaaS to AI Agents: Gone in 60 Seconds
2026/03/30
In this CISO Tradecraft episode, co-hosts G Mark Hardy and Ross Young discuss how large language models are transforming software development and shifting cybersecurity from buying Software as a Service to “Service as Software,” and ultimately to "Systems of AI agents". They explain how writing code in English enables rapid prototyping, changing cost models by reducing labor hours and increasing speed and scale, with metrics like shrinking a 40-hour threat model effort to a 10-minute agent output. Ross outlines three generations, SIEM (SaaS), SOAR (services as software), and systems of agents (AI SOC), highlighting broader, evolving detection coverage. They cover risks including underestimated maintenance, scope creep, automating bad processes, and insecure AI-generated code, and demo a prompt-built software composition analysis/SBOM tool using CycloneDX and OSV. Ross also introduces his company, Clear Capabilities, focused on agentic workforce automation for governance, privacy, architecture, and compliance. Cybersecurity's Dirty Secret: Why Most Budgets Go To Waste - https://www.amazon.com/Cybersecuritys-Dirty-Secret-Budgets-Tradecraft%C2%AE/dp/B0G26WHVTG/ Ross Young - https://www.linkedin.com/in/mrrossyoung/ Developer AI Threats - https://threats.backslash.security/
#276 - How is AI Reshaping Fraud (with Brian Long)
2026/03/23
In this episode of CISO Tradecraft, host G Mark Hardy speaks with Brian Long, CEO and co-founder of Adaptive Security, about how AI is accelerating and scaling social engineering through deepfakes, OSINT-driven personalization, and real-time conversational attacks. Brian says people remain the biggest opportunity in cyber defense, citing rapid growth in deepfake-enabled incidents and examples including a widely reported $25M wire fraud involving a fake Zoom meeting of “peers,” plus a CFO/controller case where a deepfaked CEO pushed secrecy and urgency. They argue detection alone is unreliable due to an arms race and attackers shifting to unverified channels (phone, Teams/Slack, Signal). Key mitigations include workforce awareness, stronger organizational controls (especially for hiring and payments), verification habits, and personalized training paired with AI-powered simulations and reporting/automated email handling. Big thanks to our sponsor Adaptive Security. Note, you can learn more about them by visiting their website: https://www.adaptivesecurity.com/demo/security-awareness-training
#275 - How to Secure Vibe Code (with Shahar Man)
2026/03/16
In this CISO Tradecraft episode, host G Mark Hardy interviews Shahar Man of Backslash Security about the rapidly expanding attack surface created by AI-driven “vibe coding” tools like Claude Code, Cursor, and Copilot. Shahar explains how prompting is shifting software creation, affecting education and hiring, and pushing security “further left” to the prompt, agent, MCP, skills, and rules level. He discuss risks such as loss of source integrity, excessive permissions, prompt injection, data leaks, use of unauthorized tools or accounts, and the spread of coding beyond engineering to teams like marketing and finance. Shahar argues AppSec work will transform toward securing the “sausage factory” and describes Backslash’s approach: enterprise-wide visibility, component vetting, endpoint monitoring via a local proxy, guardrails and blocking, and forwarding alerts to SOC/SIEM, with deployments scaling to thousands of workstations. Looking to get more secure on Vibe Coding? Check out the Ultimate 2026 Vibe Coding Security Buyer's Guide https://www.backslash.security/resources/vibe-coding-security-buyers-guide?utm_campaign=354642149-ciso-tradecraft&utm_source=ross-young&utm_medium=podcast-march-2026
#274 - The State of Stress in Cyber (with Steve Shelton)
2026/03/09
In this CISO Tradecraft episode, host G Mark Hardy interviews Steve Shelton (https://www.linkedin.com/in/greenshoesteve/) of Green Shoe Consulting about the “State of Stress in Cybersecurity 2025” report and why burnout is widespread among cybersecurity leaders. Shelton explains the difference between beneficial stress (eustress) and chronic distress, how threat vs challenge interpretations shape performance, and why cybersecurity’s volatile, high-stakes environment amplifies stress, especially when CISOs have responsibility without authority and limited leadership training. They discuss systemic burnout drivers such as workload, autonomy, values alignment, recognition, and leadership behaviors like trust and delegation, plus different CISO leadership styles (strategic, adaptive, tactical, operational). Shelton describes efforts to build training and measurement tools for stress and energy, comments on AI-driven uncertainty, and shares the report download link at: https://www.greenshoeconsulting.com/stateofstressreport
#273 - Creating a Wisdom-Led SOC (with Oren Saban)
2026/03/02
Your SOC is drowning in alerts, false positives, and static tuning, while attackers evolve faster than your team can respond. Analysts burn out chasing noise. Real threats slip through. And traditional metrics reward ticket volume instead of investigation quality, creating “Swiss cheese security.” In this CISO Tradecraft episode, G. Mark Hardy and Oren Saban break down the rise of the Wisdom-Led, AI-driven SOC, where AI agents handle investigations and humans focus on judgment, prevention, and faster containment. Big Thanks to Mate Security for sponsoring this episode. To learn more about their offerings please check out their website at https://mate.security/
#272 - Data Centric Platform Play (with EJ Pappas)
2026/02/23
In this episode of CISO Tradecraft, host G Mark Hardy speaks with EJ Pappas of PKWARE and Ross Young about why AI-driven threats demand a shift from platform-centric security to a data-centric strategy. CISOs still struggle to answer, “Where is our sensitive data?” as it sprawls across AI, endpoints, cloud, SaaS, and shared environments. In this conversation, we explore: Why CISOs still struggle with data visibility How vendor sprawl and fragmented toolsets create blind spots The difference between structured and unstructured data risk Why AI accelerates both defense and mistakes DLP vs. encryption: complementary, not competing controls Commonly missed exposure areas (test/QA environments, cloud storage) Compliance drivers including GLBA, PCI DSS, HIPAA, HITRUST CSF, and NIST SP 800-171Learn more at PKWARE.com/demo or contact [email protected]
#271 - A Life of Service (with Chris Inglis)
2026/02/16
In this special episode of CISO Tradecraft, host G Mark Hardy welcomes Chris Inglis, former National Cyber Director and career public servant, to delve into a wide-ranging conversation about cybersecurity leadership, public service, and life lessons. Chris shares his career journey from the Air Force Academy to piloting planes and serving at the NSA, providing unique insights along the way. They discuss the importance of integrating technology with business strategy, handling insider threats, and the future of AI in cybersecurity. Plus, enjoy some heartwarming stories about the power of culture and the joys of being grandparents.
#270 - And What is Truth?
2026/02/03
Can you still tell what’s true on the internet or does everything feel questionable now? That confusion isn’t accidental. Disinformation, deepfakes, and cyber deception are being used deliberately to manipulate attention, erode trust, and fracture societies, often faster than truth can respond. In this episode of CISO Tradecraft, we break down how modern information warfare actually works and what leaders can do to defend truth using critical thinking, verification strategies, and practical countermeasures for today’s digital battlefield.
#269 - Changing Third Party Risk Management (with Nate Lee)
2026/01/26
Third-party risk management has become a time-consuming, frustrating exercise. Security teams and vendors alike are buried under long, repetitive TPRM questionnaires that often miss what actually matters. Buyers struggle to assess real risk, while vendors waste countless hours answering low-value questions, slowing deals and draining resources. These bloated questionnaires don’t just waste time, they actively weaken security programs. Important risks get lost in the noise, assessments become checkbox exercises, and both sides grow cynical about the process. As supply chain attacks increase, relying on outdated, one-size-fits-all approaches leaves organizations exposed and ill-prepared to respond. In this episode of CISO Tradecraft, G Mark Hardy sits down with Nate Lee to explore smarter, more effective approaches to TPRM. Drawing on his experience as a CISO and entrepreneur, Nate shares practical strategies for automating assessments, asking more meaningful security questions, and using AI to reduce friction while improving insight. The conversation offers actionable guidance for buyers and vendors to streamline TPRM, focus on real risk, and build stronger, more scalable security programs. Nate Lee - https://www.linkedin.com/in/natetrustmind/ Nate Lee -  [email protected]
#268 - Zero Trust isn't a product (with George Finney)
2026/01/19
Everyone talks about Zero Trust — but very few organizations actually know how to implement it successfully. In this episode of CISO Tradecraft, host G. Mark Hardy is joined by George Finney, a practicing CISO who literally wrote the book on Zero Trust and has implemented it in one of the most challenging environments imaginable: higher education. Together, they break down: Why Zero Trust is a strategy, not a productWhy most Zero Trust initiatives fail due to people and politics, not technologyHow attackers exploit trust and lateral movementHow to implement Zero Trust without destroying culture or productivityWhat changes when AI enters the trust modelWhy AI is effectively “100% trust” — and how to reduce the blast radiusHow CISOs should explain Zero Trust and AI risk to the boardGeorge also shares practical analogies (including his now-famous restaurant model for AI) that make Zero Trust and AI security understandable for executives, IT teams, and non-technical leaders alike. If you’re serious about: Preventing breaches instead of just responding to themLimiting lateral movementSecuring AI-driven systemsTurning Zero Trust from buzzword into business strategy👉 This episode is a must-watch. George's Books: Rise of the Machine: https://www.amazon.com/Rise-Machines-Project-Trust-Story/dp/1394303718 Project Zero Trust: https://www.amazon.com/Project-Zero-Trust-Strategy-Aligning/dp/1119884845/
#267 - Busy is the New Stupid (with Ross Young)
2026/01/12
You’re working longer hours than ever… yet somehow getting less done. Sound familiar? In this episode of CISO Tradecraft, we break down why busy has become the enemy of effectiveness and why “Busy is the New Stupid.” This isn’t about working harder or faster. It’s about understanding how your time gets attacked, how distractions persist, and how even high-performing leaders fall into productivity traps. We introduce a practical framework inspired by MITRE ATT&CK to show: How meetings, emails, and interruptions gain initial access to your day Why multitasking and constant context-switching kill execution How “always-on” culture and people-pleasing create persistence What effective CISOs do to defend their time and focus on impact, not noise If you’re a CISO, security leader, or executive who feels constantly busy but strategically behind, this episode will challenge how you think about productivity—and give you a better way forward. 👉 Grab the Busy Is the New Stupid template for free https://www.cisotradecraft.com/bitns 👉 Share what’s missing and help us evolve the framework 👉 Follow CISO Tradecraft for more insights on leadership, strategy, and security Because being busy isn’t the goal. Being effective is.
#266 - Why CISOs Miss The Next Big Security Challenge (with Richard Stiennon)
2026/01/05
CISOs are expected to anticipate the next major security failure, yet the cybersecurity market is moving too fast, too fragmented, and too noisily for any leader to clearly see what’s coming next. AI is accelerating vendor sprawl, threat models are shifting mid-year, and every product claims to be “critical.” CISOs aren’t missing threats because they’re uninformed; they’re overwhelmed. By the time a risk is obvious, it’s already budgeted, deployed, and exploited. Boards ask “How did we not see this?” while CISOs are left defending decisions made with incomplete signals and outdated market maps. In this episode of CISO Tradecraft, G Mark Hardy and industry analyst Richard Stiennon break down how CISOs can regain strategic foresight. Drawing on Richard’s experience at Gartner, IT Harvest, and the Security Yearbook, they share practical ways to cut through market noise, understand where AI is truly changing security, and identify emerging risks before they become incidents giving CISOs a clearer view of what matters next.

Podcast reviews

Read CISO Tradecraft® podcast reviews


4.8 out of 5
49 reviews
★★★★★
JoshSommers 2022/07/20
So informative and logically organized
This podcast has been instrumental in transforming how I think about cyber and business risk. There’s not a lot of other podcasts that I’ve seen or he...
★★★★★
PBinNewJ 2022/02/04
Critical Information for Our Critical Infrastructure
The nature of the internet makes it incumbent on every organization to prevent intrusions, be they foreign or domestic. Corporate cybersecurity is not...
★★★★★
idavis7 2021/10/19
A great resource for those in the cyber world
This is such a great casual podcast for those looking to work their way into management in the cyber world. I recommend this to anyone who is interest...
★★★★★
Financialadventure 2020/11/07
Really interesting podcast for people wanting to be a CISO
There are a lot of podcasts on cyber security. This one has something unique. The creators have a natural energy that resonates well and I enjoy their...
check all reviews on apple podcasts

Podcast sponsorship advertising

Start advertising on CISO Tradecraft® relevant audience podcasts


What do you want to promote?