loader from loading.io

Evolving from Security to Trust, more than Just Compliance - Mike Towers - CSP #184

CISO Stories Podcast (Audio)

Release Date: 07/23/2024

Maximizing Cyber Liability Insurance: Risk, Relationships & Renewal Strategies - Mandy Andress - CSP #211 show art Maximizing Cyber Liability Insurance: Risk, Relationships & Renewal Strategies - Mandy Andress - CSP #211

CISO Stories Podcast (Audio)

Mandy Andress joins our show to discuss leveraging cyber liability insurance for risk reduction. They explore the importance of strong broker relationships and key steps for selecting or renewing a policy—starting with assessing organizational needs. Learn strategies to lower premiums while increasing coverage. Segment Resources: This segment is sponsored by Sophos. Visit to learn more about them! Visit for all the latest episodes! Show Notes:

info_outline
Breach by the Dozen: Incident Response Lessons from the Field - Mike Miller - CSP #210 show art Breach by the Dozen: Incident Response Lessons from the Field - Mike Miller - CSP #210

CISO Stories Podcast (Audio)

In this episode of the CISO Stories Podcast, we’re joined by Mike Miller, a seasoned penetration tester and audit and compliance SME, to explore the real-world impact of incident response controls. From technical to managerial and physical safeguards, Mike shares eye-opening stories from the field—including how he once penetrated a network with nothing more than a dozen doughnuts. We dive into the importance of layered security approaches and practical tips for strengthening incident response frameworks. Don’t miss this blend of humor, insight, and actionable advice for cybersecurity...

info_outline
AI Governance: Navigating Risks, Frameworks, and the Future - Rock Lambros - CSP #209 show art AI Governance: Navigating Risks, Frameworks, and the Future - Rock Lambros - CSP #209

CISO Stories Podcast (Audio)

In this episode, we sit down with author and AI expert Rock Lambros to explore the evolving landscape of AI governance. We discuss the risks of AI chatbots, comparing OpenAI and DeepSeek, and examine current and emerging governance frameworks. As AI adoption accelerates, organizations must determine the right guardrails and critical questions to ask. This conversation provides insights into how companies are shaping their AI strategies for a more secure and responsible future. Segment Resources: Visit for all the latest episodes! Show Notes:

info_outline
Privacy Under Siege: Navigating Data Theft and the BadBox Threat - Gavin Reid - CSP #208 show art Privacy Under Siege: Navigating Data Theft and the BadBox Threat - Gavin Reid - CSP #208

CISO Stories Podcast (Audio)

In this episode, we sit down with experienced CISO Gavin Reid to explore the escalating online threats to privacy, focusing on adversaries and companies illicitly scraping website data for profit. We dive into the implications of such unauthorized data collection and its impact on individual and organizational privacy. Reid also shares insights from his team’s involvement in dismantling BadBox, a coordinated global attack exploiting connected TV (CTV) devices, highlighting the intersection of cybersecurity and privacy concerns. HUMAN's Satori threat intelligence team has published the...

info_outline
Cloud Security in Higher Education: Balancing Trust and Risk - Sheena Thomas - CSP #207 show art Cloud Security in Higher Education: Balancing Trust and Risk - Sheena Thomas - CSP #207

CISO Stories Podcast (Audio)

In this episode of CISO Stories, Jess Hoffman and Sheena Thomas explore the challenges of cloud security in higher education. They discuss trust issues with cloud providers, the importance of understanding data sensitivity, and navigating regulatory compliance. Sheena highlights the vulnerabilities educational institutions face, the value of incident response playbooks, and the balance between trust and risk in cloud services. The conversation underscores the need for due diligence, awareness, and collaboration to secure higher education in the cloud era. This segment is sponsored by Fortinet...

info_outline
Cybersecurity in the Cloud: Lessons for Businesses and Beyond - Melina Scotto - CSP #206 show art Cybersecurity in the Cloud: Lessons for Businesses and Beyond - Melina Scotto - CSP #206

CISO Stories Podcast (Audio)

Jessica Hoffman and Melina Scotto discuss the evolution of cybersecurity, focusing on cloud security, business responsibilities, and the importance of basic cyber hygiene. They highlight the role of communication, consulting, and integrating security into business operations, concluding with advice for future cybersecurity professionals. This segment is sponsored by Fortinet Cloud Security. Visit to learn more about them! Visit for all the latest episodes! Show Notes:

info_outline
Cloud Security for SMBs: Strategies, Risks, and Resources - Adam John - CSP #205 show art Cloud Security for SMBs: Strategies, Risks, and Resources - Adam John - CSP #205

CISO Stories Podcast (Audio)

Jess and Adam discuss cloud security challenges for SMBs, emphasizing strategic planning, compliance with regulations like CMMC, and vendor due diligence. They highlight common pitfalls like the illusion of security and inadequate staffing while offering cost-effective solutions like virtual CISOs. Practical tips help SMBs secure their data, navigate legal concerns, and maximize available resources. This segment is sponsored by Fortinet Cloud Security. Visit to learn more about them! Visit for all the latest episodes! Show Notes:

info_outline
Cloud Security at Risk: Tackling Misconfigurations Head-On - Nadia Mazzarolo - CSP #204 show art Cloud Security at Risk: Tackling Misconfigurations Head-On - Nadia Mazzarolo - CSP #204

CISO Stories Podcast (Audio)

In this episode, we dive into the critical role of proper configurations in cloud environments and why misconfigurations remain the leading cause of security breaches. From overly permissive access controls to unencrypted data stores and default credentials left unchanged, we explore real-world examples that adversaries exploit. Learn how organizations can mitigate these risks through proactive monitoring, automated tools, and a culture of security-first thinking. Tune in to uncover actionable insights to keep your cloud infrastructure secure. This segment is sponsored by Fortinet Cloud...

info_outline
Cloud Security: Lessons Learned and Applied to Emerging Tech - Bertrum Carroll - CSP #203 show art Cloud Security: Lessons Learned and Applied to Emerging Tech - Bertrum Carroll - CSP #203

CISO Stories Podcast (Audio)

Bertrum Carroll dives into the evolution of cloud service adoption, comparing early concerns—like data storage, access, and usage—to current apprehensions about AI. We explore how leadership can empower teams with the right training to harness technology effectively. Learn why understanding the shared responsibilities between providers and customers is critical for cloud security success. This segment is sponsored by Fortinet Cloud Security. Visit to learn more about them! Visit for all the latest episodes! Show Notes:

info_outline
Identity Challenges in Manufacturing - Tammy Klotz - CSP #202 show art Identity Challenges in Manufacturing - Tammy Klotz - CSP #202

CISO Stories Podcast (Audio)

In this episode, we’re joined by Tammy Klotz, a 3x CISO in the manufacturing industry, to explore identity security challenges in manufacturing environments. Tammy discusses the differences in access management for frontline workers versus knowledge workers, touching on the unique devices and role-based training requirements. Tune in to learn how tailored security solutions are key to managing access across diverse user groups in industrial settings. This segment is sponsored by CyberArk. Visit to learn more about them! This segment is sponsored by Saviynt. Please visit to learn more and...

info_outline
 
More Episodes

CISOs need to enhance their strategic influence and operational impact within their organizations. This calls for a departure from traditional, insular security approaches towards a partnership model that aligns security initiatives with business growth and value. By adopting an attitude of listening, humility, and interdisciplinary collaboration, CISOs can transcend fear-based justifications for investment and instead, demonstrate how robust cyber security measures contribute to the overall health and success of the business. Such an evolution in the CISO role is essential for building resilient, forward-looking organizations that view security as a cornerstone of their strategic endeavors.

In the combined context of Resilience and Reputation and Trust, CISOs must orchestrate a delicate balance between robust defensive measures and the cultivation of a strong, trustworthy brand. At this juncture, resilience becomes more than just a technical safeguard; it is about ensuring the continuity and reliability that stakeholders have come to expect. This reliability directly feeds into the organization's reputation, setting the stage for trust to be the cornerstone of all engagements—internal and external. The journey from a reactive security posture to one that is proactive and business-aligned requires that CISOs embed security consciousness into the corporate DNA. As they reach these advanced stages, CISOs transform their roles from protectors to strategic enablers, guiding their organizations through the digital landscape with a clear vision for safeguarding and enhancing both operational fortitude and brand integrity. Security thus becomes an integral part of the value proposition, fostering trust and loyalty among customers, and cementing the organization's reputation as a leader in responsible business practices in the digital age.

Segment Resources:

Webcast: https://www.scmagazine.com/cybercast/the-regulatory-landscape-in-2030-what-you-need-to-know

Podcast (Enterprise Security Weekly): https://www.scmagazine.com/podcast-segment/11416-the-rise-of-regops-the-need-for-compliance-automation-travis-howerton-esw-313

News/interview: https://www.scmagazine.com/news/generative-ai-not-just-revolutionary-but-evolutionary

This segment is sponsored by RegScale. Visit https://cisostoriespodcast.com/regscale to learn more about them!

Visit https://cisostoriespodcast.com for all the latest episodes!

Show Notes: https://cisostoriespodcast.com/csp-184