The Cyber Ranch Podcast
Ride the cyber trails with two CISOs (Allan Alford and Drew Simonis) and a diverse group of friends and experts who bring a human perspective to cybersecurity.
Episodes
Wednesday Jun 28, 2023
The Real Implications of Contemporary Exploits with Anne Marie Zettlemoyer
Wednesday Jun 28, 2023
Wednesday Jun 28, 2023
The MOVEit breach has been top of mind, especially with Solar Winds and Colonial Pipeline and log4j and all the others having been so recent. It is easy to blame the victims. It is easy to make excuses that nobody can defend against a Zero Day. There are a lot of easy responses to these kinds of affairs.
But what Allan and Anne Marie Zettlemoyer get into in this episode is a variety of questions around the assumptions:
Start with a quick summary of the MOVEit exploit and Clop.
How does this attack compare to SolarWinds?
What can we do to prepare for zero-day exploits?
Is society (and the business world) getting jaded to ransomware attacks and breaches? Is this affecting their investments in cyber?
Is a post-breach CISO really rolling in the assets and resources the way so many assume?
What are the long-term implications for a business, its stock prices, and its CISO investment?
This is another episode that strives to get deeper than the surface. We hope you learn something from it, and we hope you enjoy it as well. Y'all be good now!
Sponsored by our good friends at Dazz:
Dazz takes the pain out of the cloud remediation process using automation and intelligence to discover, reduce, and fix security issues—lightning fast. Visit Dazz.io/demo and see for yourself.
Thursday Jun 22, 2023
Zero Trust & DSPM with Claude Mandy - SPECIAL LIVE EDITION
Thursday Jun 22, 2023
Thursday Jun 22, 2023
This episode was recorded LIVE at the 2023 Symmetry Systems Unconference on Zero Trust, adjunct to RSAC 2023.
Allan is joined by his friend Claude Mandy, former CISO, former analyst, and now Chief Evangelist at Symmetry Systems. Like Allan, Claude is a Zero Trust enthusiast. The podcast was the capstone to a long day of Zero Trust presentations, panels, book reviews and other great topics and conversations.
Join Allan and Claude at this live recording that covers:
- How does DSPM fit into Zero Trust?
- Allan's victory at a recent Digital Fight Club event where he championed Zero Trust
- Overcoming Zero Trust marketing hype
- Is Zero Trust a framework, an architecture, or something else? Hint: Claude says it's something else.
- What are the biggest challenges in implementing Zero Trust?
- What are the benefits to the business of Zero Trust?
- Security is about the intersection of Data & Entities - not about Assets
- What are the most exciting aspects of RSAC 2023 for Claude and Allan?
Wednesday Jun 21, 2023
Money with Nick Vigier
Wednesday Jun 21, 2023
Wednesday Jun 21, 2023
Money is the hardest thing for a CISO to acquire. As with last week's show on Time, Money has to be spent wisely as well. Perhaps the tricks to spend it wisely directly relate to how we can acquire more the next cycle to achieve the mission we know we need to achieve. In this episode we cover:
- What are the best methods for securing a budget?
- How do you structure your budget to align with business costs (COGS, R&D, CAC...)?
- What are some good ways to save money as a CISO?
- How do you best lower vendor costs for the long term?
- How can a CISO help make money for the business?
Sponsored by our good friends at Dazz:
Dazz takes the pain out of the cloud remediation process using automation and intelligence to discover, reduce, and fix security issues—lightning fast. Visit Dazz.io/demo and see for yourself.
Wednesday Jun 14, 2023
Time w/ Paul Robinson
Wednesday Jun 14, 2023
Wednesday Jun 14, 2023
Time is one of our most precious commodities as security practitioners. And yet we have traditional time sinkholes where we waste time, lose time, and spend time. Join Allan and Paul Robinson, Founder and Managing Director at Tempus Network, as they explore several of these areas and give concrete tips on how to save time as security practitioners:
- Keeping up with industry trends
- Managing cyber incidents
- Third-party questionnaires (both directions!)
- Vendor onboarding
- Work from home vs. going into the office
Sponsored by our good friends at Dazz:
Dazz takes the pain out of the cloud remediation process using automation and intelligence to discover, reduce, and fix security issues—lightning fast. Visit Dazz.io/demo and see for yourself.
Wednesday Jun 07, 2023
FedRAMP, StateRAMP, TX-RAMP with Jay Adams
Wednesday Jun 07, 2023
Wednesday Jun 07, 2023
Join Allan and his guest Jay Adams, CISO @ Enchoice and former security architect for several large private and public sector efforts - from M&A activities to massive public portals.
Jay is going through TX-RAMP right now, and both he and Allan have done research on FedRAMP and StateRAMP as well.
What are the differences? Why might you choose one over the other? What are the gotchas?
This is a great show and you'll get to learn a bit about Allan's brief foray into state government as well...
Sponsored by our good friends at Dazz:
Dazz takes the pain out of the cloud remediation process using automation and intelligence to discover, reduce, and fix security issues—lightning fast. Visit Dazz.io/demo and see for yourself.
Monday Jun 05, 2023
RSAC 2023 Special Edition Campfire Chats - Part 2
Monday Jun 05, 2023
Monday Jun 05, 2023
This is Part 1 of an incredible series of interviews Allan conducted live at RSA 2023. Guests include:
Gary Hayslip, CISO @ Softbank Investment Advisers
Michael Calderin, CISO @ YAGEO Group
David Cross, CISO @ Oracle SaaS Cloud
Audra Streetman, Security Strategist @ Splunk
Adrian Peters, CISO @ Vista Equity Partners
Robin Sundaram, CISO @ RELX
Merritt Baer, Office of the CISO @ AWS
Rob Wood, CISO @ Centers for Medicare & Medicaid Services
Bryan Green, CISO Americas @ ZScaler
Stephanie Derdouri, Sr. Manager, Information Security and Technology Risk Management @ Capital Group
Andres Andreu, CISO @ 2U
Paul Love, CISO & Chief Privacy Officer @ Co-op Solutions
Royce Markose, former CISO
Bob Schuetter, CISO @ Ashland
Susan Thomas, CEO @ 10Fold
Brian Markham, CISO @ EAB
Ken Foster, VP of IT GRC @ FLEETCOR
Elizabeth Martinez, Account Exec @ ThreatLocker
Josiah Dykstra, Senior Fellow, Office of Innovation @ The NSA
Kevin Brown, CEO @ Innit
Brent Deterding, CISO @ Afni
Audra Streetman, Security Strategist @ Splunk
Wendy Whitmore, SVP, Unit 42 @ Palo Alto Networks
I ask my guests several questions including:
How do you impact the top and bottom line?
What topics are you tired of in cybersecurity?
There are also some special interviews at the end - discussions about the RSA conference itself, tech stack sprawl, and personal branding and marketing for CISOs. Oh - and a question about how vendors and CISOs can work better together AND a conversation about how government and industry can work together in cybersecurity.
Give this one a listen! It's jam-packed with great insights!
Sponsored by AttackIQ & Semperis.
AttackIQ offers a new fully managed breach and attack simulation service. They are the premier provider of MITRE ATT&CK-based security control validation. https://attackiq.com
Semperis provides the industry's most comprehensive Active Directory and Azure AD cyber resilience platform, supported by specialized AD incident response expertise. https://semperis.com
Wednesday May 31, 2023
1% Leadership with Andy Ellis
Wednesday May 31, 2023
Wednesday May 31, 2023
This week's show is exciting because Allan has been waiting for Andy's book on leadership to come out for quite some time. The book is called “1% Leadership – Master The Small, Daily Improvements That Set Great Leaders Apart”, and it consists of 54 chapters - each of which presents a specific facet of good leadership in a nearly "buffet style" manner. You can pick and choose topics that resonate with you and dive right in.
Allan picked 6 chapters that resonated with him in particular and got Andy to elaborate:
Chapter 1 - “Personal improvement is a prerequisite to leading professionally”
Chapter 6 - “Gift kindness where it isn’t expected”
Chapter 8 – “An uncompelled apology unburdens everyone”
Chapter 13 - "Your wellness is one of the greatest assets you control" (Listen as Andy hits Allan straight in the feels on this topic)
Chapter 24 – "People need to see versions of themselves to feel welcome"
Chapter 35 - "In general, be vague"
The book is amazing, these particular chapters are amazing, and Andy's expounding upon them is amazing as well!
Y'all be good now!
Wednesday May 24, 2023
Will LLM AI Close The Bad Guys’ Skills Gap? with Adrian Sanabria
Wednesday May 24, 2023
Wednesday May 24, 2023
This episode is a bit scary. Adrian Sanabria, who on an earlier show busted many cybersecurity myths, is back again, this time analyzing the impact of Large Language Model Artificial Intelligence on a hypothesized skills gap on the bad guy side.
Premise One: Given how many organizations that are vulnerable and that have NOT been breached, the bad guys are suffering the same skills gap we are.
Premise Two: Exploit attacks (think of exploits as ransomware, data hostage situations, threats to publish breached data, etc.) can benefit from LLM AI.
It's really that simple a connecting of the dots. Adrian and Allan deconstruct the steps of an exploit attack, analyze the capabilities of LLM AI and cross-reference the two.
If they are right, then we have a burden of leveraging and learning LLM AI ourselves, as quickly as possible...
Sponsored by our good friends at Dazz:
Dazz takes the pain out of the cloud remediation process using automation and intelligence to discover, reduce, and fix security issues—lightning fast. Visit Dazz.io/demo and see for yourself.
Monday May 22, 2023
RSAC 2023 SPECIAL EDITION Campfire Chats - Part 1
Monday May 22, 2023
Monday May 22, 2023
This is Part 1 of an incredible series of interviews Allan conducted live at RSA 2023. Guests include:
Chris Kennedy, CISO @ Citadel
Gary Hayslip, CISO @ Softbank Investment Advisers
Michael Calderin, CISO @ YAGEO Group
Reet Kaur, CISO @ Portland Community College
Rob LaMagna-Reiter, CISO @ Hudl
Matthew Lang, vCISO
David Cross, CISO @ Oracle SaaS Cloud
Audra Streetman, Security Strategist @ Splunk
Vishal Amin, General Manager of Security Solutions (Federal) @ Microsoft
Adrian Peters, CISO @ Vista Equity Partners
Kelly Shortridge, Author of “Security Chaos Engineering: Sustaining Resilience in Software and Systems”
Robin Sundaram, CISO @ RELX
Merritt Baer, Office of the CISO @ AWS
Tim Rohrbaugh, former CISO & Industry Leader
Rob Wood, CISO @ Centers for Medicare & Medicaid Services
Bryan Green, CISO Americas @ ZScaler
Stephanie Derdouri, Sr. Manager, Information Security and Technology Risk Management @ Capital Group
Andres Andreu, CISO @ 2U
Paul Love, CISO & Chief Privacy Officer @ Co-op Solutions
Royce Markose, former CISO
Bob Schuetter, CISO @ Ashland
I ask my guests several questions:
What is the best part of RSAC 2023 for you?
What is the single most critical skill a security leader needs?
What's missing in cybersecurity?
What is your take on Purple Teaming and MITRE ATT&CK?
How do you co-lead the organization?
There is also a VERY special interview with James Stanley, Chief of Product Development at CISA at the end. Don't miss it!
Sponsored by Semperis & AttackIQ.
Semperis provides the industry's most comprehensive Active Directory and Azure AD cyber resilience platform, supported by specialized AD incident response expertise. https://semperis.com
AttackIQ offers a new fully managed breach and attack simulation service. They are the premier provider of MITRE ATT&CK-based security control validation. https://attackiq.com
Wednesday May 17, 2023
Two Founder CEOs with Merav Bahat and Mickey Bresman
Wednesday May 17, 2023
Wednesday May 17, 2023
Leadership skills, technical skills, cybersecurity skills, pluck, drive and determination are all on display as Allan interviews Merav Bahat, CEO @ Dazz and Mickey Bresman, CEO @ Semperis.
Dazz has completed a Series A investment round. Semperis a Series C. It turns out that the skills each CEO needs are still remarkably the same.
Saddle up for another episode, where Allan asks his guests:
What’s the coolest thing that has happened for you or to you as a startup CEO?
What has been the biggest single challenge?
What are your top 3 tenets of leadership?
What is the purpose of vision and how clear must it be?
What is the purpose of mission and how clear must it be?
What is your advice to those who would want to become a startup CEO?
Sponsored by our good friends at Dazz:
Dazz takes the pain out of the cloud remediation process using automation and intelligence to discover, reduce, and fix security issues—lightning fast. Visit Dazz.io/demo and see for yourself.
Wednesday May 10, 2023
Security Chaos Engineering with Kelly Shortridge
Wednesday May 10, 2023
Wednesday May 10, 2023
What is security chaos engineering? You may remember Kelly Shortridge, our very first guest, who came on the show to talk about behavioral economics and cybersecurity. Well Kelly is back to talk about her new book, "Security Chaos Engineering: Sustaining Resilience in Software and Systems".
Security chaos engineering is derived from chaos engineering, a relatively new discipline in software development that seeks to test distributed computing systems to ensure that they withstand unexpected disruptions. It's all about resilience, in other words. Security chaos engineering seeks to do the same for the security of such software systems.
Kelly breaks down her book during a lively conversation featuring an opinion or two her cat, Link (yes, a Zelda reference!):
Who should read this book?
Resilience in software and systems
Systems-oriented security
Architecting and designing
Building and delivering
Operating and observing (Allan's favorite chapter as it intersects with one of his Zero Trust tenets)
Responding and recovering
Platform resilience engineering
Security chaos experiments (a very fun chapter!)
Case studies
Note that the book is peppered with references and quotes from other disciplines. We would expect no less from Kelly.
Sponsored by our good friends at Dazz:
Dazz takes the pain out of the cloud remediation process using automation and intelligence to discover, reduce, and fix security issues—lightning fast. Visit Dazz.io/demo and see for yourself.
Wednesday May 03, 2023
The 9-Layer Cybersecurity Program Cake with Bryan Liebert
Wednesday May 03, 2023
Wednesday May 03, 2023
Bryan Liebert is one smart cookie. Who bakes cybersecurity cakes. But seriously, Bryan has been a CISO, consultant, architect, and has served many other roles in cybersecurity. His specialty is creating simple to digest (we could not help it, sorry!) models for managing and reporting on cybersecurity programs and practices.
Join Bryan and Allan as they serve up (we're still doing it!) a lively and informative episode!
Sponsored by our good friends at Dazz:
Dazz takes the pain out of the cloud remediation process using automation and intelligence to discover, reduce, and fix security issues—lightning fast. Visit Dazz.io/demo and see for yourself.
Wednesday Apr 26, 2023
Four Problems with Cybersecurity with Adrian Wright
Wednesday Apr 26, 2023
Wednesday Apr 26, 2023
Adrian Wright, "The Cynical CISO" of LinkedIn fame, joins Allan to discuss four areas where cybersecurity is perhaps getting it wrong:
Cybersecurity viewed as a necessary evil, related to The Twilight Zone
Ownership, Authority, Accountability: Inventory and Means of Control
Are WE the baddies?
(Largely) Forgotten Security Principles
Allan and Adrian dissect cybersecurity practice in this great episode!
Sponsored by our good friends at Dazz:
Dazz takes the pain out of the cloud remediation process using automation and intelligence to discover, reduce, and fix security issues—lightning fast. Visit Dazz.io/demo and see for yourself.
Monday Apr 24, 2023
The Cloud and the Big Bang of Data with Cecil Pineda and Gene Moore
Monday Apr 24, 2023
Monday Apr 24, 2023
Join us for a SPECIAL EDITON! episode of The Cyber Ranch Podcast LIVE! from CISO XC in Dallas-Fort Worth, Texas!
The topic is data security: its challenges and how to overcome them.
Joining Allan are Cecil Pineda of R1 ("Cecil the CISO") and Gene Moore of Securiti.
The conversation is live and lively, recorded as-is and delivered to you.
Enjoy!
Sponsored by Securiti - https://securiti.ai/
Wednesday Apr 19, 2023
The Blurring of Personal & Corporate Security with Leigh Honeywell
Wednesday Apr 19, 2023
Wednesday Apr 19, 2023
We always think of cybersecurity startups as companies who contribute to the tech stack in an organizational environment - usually the enterprise. We also think of personal cybersecurity in terms of protecting Grandma or our kids from the bad guys. But these two worlds intersect far more than you would think, and the techniques for addressing these problems intersect as well.
This week Allan is joined by Leigh Honeywell, CEO at Tall Poppy, to discuss these intersections. Leigh is uniquely qualified, as her non-traditional startup addresses "personal security outside the firewall", which includes executive protection...
Sponsored by our good friends at Dazz:
Dazz takes the pain out of the cloud remediation process using automation and intelligence to discover, reduce, and fix security issues—lightning fast. Visit Dazz.io/demo and see for yourself.
Wednesday Apr 12, 2023
Design Partnerships with Emily Heath
Wednesday Apr 12, 2023
Wednesday Apr 12, 2023
Emily Heath is a well-known and well-respected figure in cybersecurity. She has been a CISO three times in a variety of industries, including software and a major airline. She has been in law enforcement, is a partner at a VC firm, and serves on boards of directors as well.
With this wealth of experience she has come to value design partnerships - working with small startups to help craft their solutions to meet hers and their needs.
But what are some of the challenges in design partnerships? Allan and Emily tackle the following questions:
What inspires one towards design partnerships?
How can a practitioner design partner help a first-time founder?
Where does the innovation come from in this model?
Does the vast amount of cyber vendors help or hinder the design partnership model?
What are the pros and cons of alternatives to design partnership?
How does a practitioner get started with design partnership?
Sponsored by our good friends at Dazz:
Dazz takes the pain out of the cloud remediation process using automation and intelligence to discover, reduce, and fix security issues—lightning fast. Visit Dazz.io/demo and see for yourself.
Wednesday Apr 05, 2023
All About Advisory Boards with Karla Reffold
Wednesday Apr 05, 2023
Wednesday Apr 05, 2023
This week Allan is joined by Karla Reffold, COO at Orpheus Cyber. Yes, that makes her a vendor, but, yes, she follow's the show's rules: She is a friend, not a sponsor; she is not all vendory; and most importantly she is a subject matter expert on this week's topic: advisory boards!
In fact, Karla has written an ebook on the subject which is available here:
https://karlareffold.co.uk/advisory-boards-guide-book
Topics covered in the show:
- The ethical entanglements of being on an advisory board
- Paid vs. unpaid advisory board roles (and cash vs. equity)
- Advisory board roles as kickbacks (yes, it happens)
- Advisors who are customers vs. advisors who are not
- Do advisory board roles help or hurt a CISO's career?
Enjoy! Y'all be good!
Wednesday Mar 29, 2023
CISO vs. Individual Contributor Perspectives w/ William Klusovsky
Wednesday Mar 29, 2023
Wednesday Mar 29, 2023
Becoming a CISO means changing a lot of perspectives. Individual contributors need to learn this, and the CISO is the best one to teach them. "They're never going to get it!" is a mantra used by both sides of that dialogue, and that is not a solution. Will and Allan discuss:
- What precepts really are "obvious"
- How does one onboard leadership and business perspectives?
- What should CISOs do to ensure their teams gain those perspectives?
- What can individual contributors do to ensure that they gain those perspectives?
- The value of self-teaching and mentorship
- Beliefs we should get rid of
It's a great conversation! Ya'll enjoy it!
Wednesday Mar 22, 2023
How to Trust Your Vendors - A Scary Case Study with Paul Moreno
Wednesday Mar 22, 2023
Wednesday Mar 22, 2023
This episode is a story about an entire vendor encounter gone horribly wrong. Allan is joined by Paul Moreno, VP of InfoSec at Catawii, formerly SVP of Cybersecurity at Adyen, investor and advisor. Paul found a cybersecurity vendor. Paul found good references. Paul got referrals from peers. Paul did a PoC. And after that, it all went downhill. Paul was kind enough to share his story as he and Allan pick apart the failings and deliberate on ways we can all avoid such encounters.
Topics covered are:
- How to spot lies
- Vetting the vendor's internal security landscape
- ISO 27001 Statement of Applicability
- Breaches and whistleblowing
- GDPR violations in charging to delete data
It is a story you will want to hear, and the analysis just might save you some pain down the road...
Sponsored by Allan Alford Consulting https://allanalford.com/about
Wednesday Mar 15, 2023
Tech Teams, GRC Teams, and the CISO with Dr. Mike Brass
Wednesday Mar 15, 2023
Wednesday Mar 15, 2023
Join Allan and Dr. Mike Brass (whose degree is in archaeology!) as they jointly explore the technical side of the house vs. the GRC side of the house, noting that GRC can be a great path to CISO.
Hear Mike's journey from IT technician to GRC to CISO.
Topics Allan and Mike cover:
The tension between tech teams and GRC teams, and how a CISO can bridge the two teams
Reasons why GRC makes such a great background for the CISO role (and how to get there)
What engineering/architecture folks should know about GRC
What GRC folks should know about the tech side of the house
What the rest of the business should know about GRC
You also get to hear Mike's journey, which has spanned small and large companies, government think tanks and more!
Sponsored by Allan Alford Consulting https://allanalford.com
Wednesday Mar 08, 2023
How Do We Embrace Imperfection with Robin Sundaram
Wednesday Mar 08, 2023
Wednesday Mar 08, 2023
We have this idea that we can be perfect. And we know that idea is unsound. So we settle for imperfection. But are we doing that purposefully? Do we have a conscious plan for embracing imperfection? How can we, as cyber professionals, embrace our imperfection meaningfully and with intent?
Join Allan and Robin Sundaram as they explore this topic, covering areas such as:
NIST CSF is all about imperfection
Embracing CMDB imperfection
Vulnerability Management and Patch Management
Product/Project Rollouts
Dev teams and the pipeline
Imperfection and GRC
It's a great conversation and you are sure to learn a thing or two!
Sponsored by Allan Alford Consulting: https://allanalford.com
Wednesday Mar 01, 2023
Technical Case vs. Business Case with Omkhar Arasaratnam
Wednesday Mar 01, 2023
Wednesday Mar 01, 2023
In this episode, Allan is joined by Omkhar Arasaratnam, a force in the industry and an expert in the intersection of software and security (you may remember Omkhar from an earlier show about supply chain security).
They challenge each other to a game, "Technical Case vs. Business Case", where they must provide both arguments for a given technology deployment. The real subtext here is that whenever these two get together, they always lean towards a technical conversation, so they are challenging themselves.
Topics Covered:
MFA
Service Accounts
Refresh Cycles
Token Expiration
Recovery Emails
Regulatory Mandates
Biometrics
SBOM
It's a lively conversation and we hope you will find value in it!
Sponsor Links:
Thank you to our sponsor TrustMAPP for bringing this episode to life! The TrustMAPP solution gets you out of spreadsheets and slide decks and into managing, measuring and reporting on your cybersecurity with an all-in-one solution that combines cybersecurity frameworks, maturity, risk and business objectives and cross-references them to remediation costs. Find out more at https://trustmapp.com
Wednesday Feb 22, 2023
The Implications of ChatGPT and AI with Shaun Marion and ChatGPT
Wednesday Feb 22, 2023
Wednesday Feb 22, 2023
Join Allan, Shaun Marion (CISO of McDonald's) and ChatGPT itself for a lively conversation about the implications of this new tool, AI in general, and nuances about ChatGPT's usage.
Even after controls were put into place to prevent ChatGPT from helping the bad guys, Allan and Shaun were able to trick it into giving up details on hacking, authoring phishing emails and more.
Shaun and Allan explore the potential for abuse and the positive promise and excitement that this new era of AI is ushering in.
What are the societal implications of ChatGPT?
What are the positive advances of AI?
Should we be cautious with what we feed ChatGPT?
Hear answers to these questions and more on this week's lively episode.
Sponsor Links:
Thank you to our sponsor TrustMAPP for bringing this episode to life! The TrustMAPP solution gets you out of spreadsheets and slide decks and into managing, measuring and reporting on your cybersecurity with an all-in-one solution that combines cybersecurity frameworks, maturity, risk and business objectives and cross-references them to remediation costs. Find out more at https://trustmapp.com
Wednesday Feb 15, 2023
Breach Communications with Heather Noggle
Wednesday Feb 15, 2023
Wednesday Feb 15, 2023
How important are communications after your company has been breached? They can make or break customer perception, and the perception of the world. Bad communications are perceived as bad intent.
Joining Allan this week is Heather Noggle, owner of Codistac - a company that specializes in cyber communications, advocacy and awareness. She studied communications in college, and takes this stuff very seriously.
The pair cover LastPasss, Okta and Reddit breaches, comparing the bad to the good.
Topics covered:
Poor editing of communications
Willful non-communication
Obfuscation
Apologies
Letting the lawyers have their say - but not the last say
The balance between speed and accuracy
It's a great conversation and a great show.
Sponsor Links:
Thank you to our sponsor TrustMAPP for bringing this episode to life! The TrustMAPP solution gets you out of spreadsheets and slide decks and into managing, measuring and reporting on your cybersecurity with an all-in-one solution that combines cybersecurity frameworks, maturity, risk and business objectives and cross-references them to remediation costs. Find out more at https://trustmapp.com
Wednesday Feb 08, 2023
BISO Bonanza with Ann Hines, James Binford and Matt Winkeler
Wednesday Feb 08, 2023
Wednesday Feb 08, 2023
Do you want to be a CISO one day? Are you a CISO today who wants to strengthen your ties into the rest of the business? The Business Information Security Officer (BISO) role is one you should explore.
The role can vary quite a bit, as you will hear on this episode with not one, not two, but three BISOs joining Allan Alford to discuss the role and its nuances: where it fits, what is required, how it is best positioned and managed.
Allan has been a BISO himself and has managed BISOs as well, so the conversation is rapid and productive.
Join Allan along with Ann Hines (BISO @ USAA), James Binford (BISO @ Humana) and Matt Winkeler (BISO @ Equifax) as the explore the BISO role.
Sponsor Links:
Thank you to our sponsor TrustMAPP for bringing this episode to life! The TrustMAPP solution gets you out of spreadsheets and slide decks and into managing, measuring and reporting on your cybersecurity with an all-in-one solution that combines cybersecurity frameworks, maturity, risk and business objectives and cross-references them to remediation costs. Find out more at https://trustmapp.com