loader from loading.io

Maximizing Cyber Liability Insurance: Risk, Relationships & Renewal Strategies - Mandy Andress - CSP #211

CISO Stories Podcast (Audio)

Release Date: 04/14/2025

Attack Surface Management - Matt Lea - CSP #227 show art Attack Surface Management - Matt Lea - CSP #227

CISO Stories Podcast (Audio)

In this episode of CISO Stories, Jessica Hoffman sits down with Matt Lee to explore attack surface management, AWS security, and the cloud misconfigurations that can put organizations at risk. Matt shares lessons from his experience auditing cloud environments, including common AWS security gaps around identity and access management, exposed resources, security groups, and overly permissive access. The conversation also covers emerging challenges around AI agents, protecting production data, and balancing speed of innovation with security controls. From preventing cloud breaches to building...

info_outline
Cloud Security Meets AI: What CISOs Need to Govern Before They Scale - Brent Neal - CSP #226 show art Cloud Security Meets AI: What CISOs Need to Govern Before They Scale - Brent Neal - CSP #226

CISO Stories Podcast (Audio)

AI is changing cloud security fast, but the biggest challenge is not just adoption. It is governance. In this episode, Jess sits down with Brent Neil, CISO at RapidScale, to talk about what CISOs should be watching as AI becomes embedded in cloud environments, business workflows, and sensitive data systems. Brent shares practical insight on AI governance, identity and access, cloud security controls, and the risks that emerge when experimentation moves into production. The conversation explores how security leaders can support innovation without losing visibility, accountability, or trust....

info_outline
Critical Infrastructure: The Risk Hiding in Plain Sight - Jason Manar - CSP #225 show art Critical Infrastructure: The Risk Hiding in Plain Sight - Jason Manar - CSP #225

CISO Stories Podcast (Audio)

In this episode, former FBI cyber leader Jason Manar joins us to unpack the state of critical infrastructure security and why small and medium-sized businesses are more connected to it than they realize. From power, telecom, healthcare, finance, and supply chains, Jason explains how hidden dependencies can turn “not our problem” into a business-stopping event. With his FBI perspective and CISO experience, Jason shares what organizations should understand about risk, resilience, and protecting the systems we all quietly rely on. Visit for all the latest episodes! Show Notes:

info_outline
IAM for MSSPs: The Hidden Risk of Blind Trust - Dustin Sachs - CSP #224 show art IAM for MSSPs: The Hidden Risk of Blind Trust - Dustin Sachs - CSP #224

CISO Stories Podcast (Audio)

Identity is at the center of nearly every modern breach, but when IAM responsibilities are shared with MSSPs, where does trust end and accountability begin? In this episode of CISO Stories, Jessica Hoffman sits down with Dr. Dustin Sachs to explore the human side of identity and access management, including cognitive bias, automation, privilege creep, and the hidden risks of “blind trust” in real-world security operations. Visit for all the latest episodes! Show Notes:

info_outline
Cloud Security: The AI Effect & How to Proceed - Richard Marcus - CSP #223 show art Cloud Security: The AI Effect & How to Proceed - Richard Marcus - CSP #223

CISO Stories Podcast (Audio)

In this episode of CISO Stories, Jessica Hoffman speaks with Richard Marcus, CISO at Optro, about how organizations are securing cloud environments at scale. They discuss secure by design principles, infrastructure as code, continuous monitoring, and how GRC and security teams are working together more effectively. The conversation also explores the impact of AI on both defense and the evolving threat landscape, with practical insights for modern security leaders. Segment Resources: Optro Cyber Risk Playbook: This segment is sponsored by BlinkOps. Blink Micro-Agents stop AI threats with...

info_outline
From Alerts to Action: Making Public–Private Threat Intel Actually Useful - Ian Washburn - CSP #222 show art From Alerts to Action: Making Public–Private Threat Intel Actually Useful - Ian Washburn - CSP #222

CISO Stories Podcast (Audio)

Threat intelligence too often arrives as a steady stream of alerts that don’t translate into clear, timely decisions. This episode explores how public-sector intel flows today through channels like CISA, MS-ISAC, and CIS—and why changes in funding and distribution can reshape what organizations actually receive and when. We also imagine an all-in state approach, where states take a bigger role in getting actionable cyber intel to local businesses and organizations. From a higher-ed security leadership lens, we connect student data privacy and regulatory realities to the broader...

info_outline
Beyond Vendor Risk: Real-Time GRC, AI, and Protecting App User Data - Jadee Hanson - CSP #221 show art Beyond Vendor Risk: Real-Time GRC, AI, and Protecting App User Data - Jadee Hanson - CSP #221

CISO Stories Podcast (Audio)

CISO Jadee Hanson shares how Vanta “drinks its own champagne,” running on NIST CSF with quarterly baseline reviews and using Vanta’s GRC platform to turn every release into live UAT for privacy, governance, and compliance. We rethink third-party management—why point-in-time risk scores are fading and how AI drives continuous monitoring and outcome-based assurance. Bottom line: don’t just audit—instrument your controls and prove trust in real time. Visit for all the latest episodes! Show Notes:

info_outline
Keys Without People — John Heasman on Cleaning Up Non-Human Access - John Heasman - CSP #220 show art Keys Without People — John Heasman on Cleaning Up Non-Human Access - John Heasman - CSP #220

CISO Stories Podcast (Audio)

Title: Keys Without People” — John Heasman on Cleaning Up Non-Human Access Summary: John breaks today’s non-human identity mess into three buckets: core tools your business runs on, old/one-off integrations that linger, and engineer tokens left behind. His playbook is simple: decide what’s truly critical, assign a clear owner, keep access minimal, and review it on a schedule. With AI spawning even more “non-human users,” basics done well—prioritize, tighten, rotate, repeat—win the day. This segment is sponsored by Saviynt. Visit to learn more about them! Visit for all the...

info_outline
Agents at the Door: Vetting Non-Human Identities in External IAM - Rakesh Soni - CSP #219 show art Agents at the Door: Vetting Non-Human Identities in External IAM - Rakesh Soni - CSP #219

CISO Stories Podcast (Audio)

This episode was about agentic IAM—what it is and the risks that come with letting non-human agents act for customers. We defined external IAM, then traced how the industry moved from basic login and MFA to consent, delegation, and now agent-to-agent interactions. Along the way we unpacked key risks for CISOs and practitioners to consider. Segment Resources: Visit for all the latest episodes! Show Notes:

info_outline
ATT&CK → ATLAS: A CISO’s Blueprint for AI Governance - Sandy Dunn - CSP #218 show art ATT&CK → ATLAS: A CISO’s Blueprint for AI Governance - Sandy Dunn - CSP #218

CISO Stories Podcast (Audio)

CISO Sandy Dunn breaks down her blueprint for AI-ready defense—pairing MITRE ATT&CK v18 with MITRE ATLAS to move from policy to behavior-based detections. We hit practical AI governance, her early focus on defending and understanding AI, and how OWASP GenAI tools turn checklists into action. Segment Resources: Article:   AI Cheat Sheet:  OWASP LLM Governance Checklist: OWASP Threat Defense COMPASS: Visit for all the latest episodes! Show Notes:

info_outline
 
More Episodes

Mandy Andress joins our show to discuss leveraging cyber liability insurance for risk reduction. They explore the importance of strong broker relationships and key steps for selecting or renewing a policy—starting with assessing organizational needs. Learn strategies to lower premiums while increasing coverage.

Segment Resources: https://www.elastic.co/

This segment is sponsored by Sophos. Visit https://cisostoriespodcast.com/sophos to learn more about them!

Visit https://cisostoriespodcast.com for all the latest episodes!

Show Notes: https://cisostoriespodcast.com/csp-211