TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    CISO Tradecraft®

    You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level.

    © Copyright 2025, National Security Corporation. All Rights Reserved

    Advertise

    Copyright: © Copyright 2024 All rights reserved.

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    #176 - Reality-Based Leadership (with Alex Dorr) Apr 08, 2024
    Show notes

    In this episode of CISO Tradecraft, host G Mark Hardy welcomes Alex Dorr to discuss Reality-Based Leadership and its impact on reducing workplace drama and enhancing productivity. Alex shares his journey from professional basketball to becoming an evangelist of reality-based leadership, revealing how this approach helped him personally and professionally. They delve into the concepts of SBAR (Situation, Background, Analysis, Recommendation) for effective communication, toggling between low self and high self to manage personal reactions, and practical tools like 'thinking inside the box' to confront and solve workplace issues within given constraints. The conversation underscores the importance of focusing on actionable strategies over arguing with the drama and reality of workplace dynamics, aiming to foster a drama-free, engaged, and productive work environment.

    Alex Dorr's Linkedin: https://www.linkedin.com/in/alexmdorr/

    Reality-Based Leadership Website: https://realitybasedleadership.com/

    Transcripts: https://docs.google.com/document/d/1wge0pFLxE4MkS6neVp68bdz8h9mHrwje

    Chapters

    • 00:00 Introduction
    • 00:57 Alex Dorr's Journey from Basketball to Leadership Expert
    • 03:54 The Core Principles of Reality-Based Leadership
    • 06:20 Understanding the Human Condition in the Workplace
    • 09:19 Tackling Workplace Drama with Reality-Based Leadership
    • 11:58 The Power of Positive Energy Management
    • 17:42 Navigating Unpreferred Realities and Finding Impact
    • 19:44 Reality-Based Leadership in Action: Techniques and Outcomes
    • 23:12 The Importance of Skill Development Over Perfecting Reality
    • 24:32 The Challenge of Employee Engagement
    • 25:49 Secrets to Embracing Reality and Taking Action
    • 25:58 Leadership vs. Management: Navigating Workplace Dynamics
    • 28:28 Empowering Employees with the SBAR Framework
    • 34:04 Addressing Venting and Negative Behaviors
    • 36:17 Developing People: The Core of Leadership
    • 37:50 Choosing Happiness Over Being Right
    • 40:15 Integrating New Leadership Models and Making Them Stick
    • 46:24 Concluding Thoughts and Contact Information

    #175 - Navigating NYDFS Cyber Regulation Apr 01, 2024
    Show notes

    This episode of CISO Tradecraft dives deep into the New York Department of Financial Services Cybersecurity Regulation, known as Part 500. Hosted by G Mark Hardy, the podcast outlines the significance of this regulation for financial services companies and beyond. Hardy emphasizes that Part 500 serves as a high-level framework applicable not just in New York or the financial sector but across various industries globally due to its comprehensive cybersecurity requirements. The discussion includes an overview of the regulation's history, amendments to enhance governance and incident response, and a detailed analysis of key sections such as multi-factor authentication, audit trails, access privilege management, and incident response. Additionally, the need for written policies, designating a Chief Information Security Officer (CISO), and ensuring adequate resources for implementing a cybersecurity program are highlighted. The podcast also offers guidance on how to approach certain regulatory mandates, emphasizing the importance of teamwork between CISOs, legal teams, and executive management to comply with and benefit from the regulation's requirements.

    AuditScripts: https://www.auditscripts.com/free-resources/critical-security-controls/

    NYDFS: https://www.dfs.ny.gov/industry_guidance/cybersecurity

    Transcripts: https://docs.google.com/document/d/1CWrhNjHXG1rePtOQT-iHyhed2jfBaZud

    Chapters

    • 00:00 Introduction
    • 00:35 Why Part 500 Matters Beyond New York
    • 01:48 The Evolution of Financial Cybersecurity Regulations
    • 03:20 Understanding Part 500: Definitions and Amendments
    • 08:44 The Importance of Multi-Factor Authentication
    • 14:33 Navigating the Complexities of Cybersecurity Regulations
    • 20:23 The Critical Role of Asset Management and Access Privileges 25:37 The Essentials of Application Security and Risk Assessment
    • 31:11 Incident Response and Business Continuity Management
    • 32:36 Concluding Thoughts on NYDFS Cybersecurity Regulation

    #174 - OWASP Top 10 Web Application Attacks Mar 25, 2024
    Show notes

    In this episode of CISO Tradecraft, host G. Mark Hardy delves into the crucial topic of the OWASP Top 10 Web Application Security Risks, offering insights on how attackers exploit vulnerabilities and practical advice on securing web applications. He introduces OWASP and its significant contributions to software security, then progresses to explain each of the OWASP Top 10 risks in detail, such as broken access control, injection flaws, and security misconfigurations. Through examples and recommendations, listeners are equipped with the knowledge to better protect their web applications and ultimately improve their cybersecurity posture.

    OWASP Cheat Sheets: https://cheatsheetseries.owasp.org/

    OWASP Top 10: https://owasp.org/www-project-top-ten/

    Transcripts: https://docs.google.com/document/d/17Tzyd6i6qRqNfMJ8OOEOOGpGGW0S8w32

    Chapters

    • 00:00 Introduction
    • 01:11 Introducing OWASP: A Pillar in Cybersecurity
    • 02:28 The Evolution of Web Vulnerabilities
    • 05:01 Exploring Web Application Security Risks
    • 07:46 Diving Deep into OWASP Top 10 Risks
    • 09:28 1) Broken Access Control
    • 14:09 2) Cryptographic Failures
    • 18:40 3) Injection Attacks
    • 23:57 4) Insecure Design
    • 25:15 5) Security Misconfiguration
    • 29:27 6) Vulnerable and Outdated Software Components
    • 32:31 7) Identification and Authentication Failures
    • 36:49 8) Software and Data Integrity Failures
    • 38:46 9) Security Logging and Monitoring Practices
    • 40:32 10) Server Side Request Forgery (SSRF)
    • 42:15 Recap and Conclusion: Mastering Web Application Security

    #173 - Mastering Vulnerability Management Mar 18, 2024
    Show notes

    In this episode of CISO Tradecraft, host G Mark Hardy delves into the critical subject of vulnerability management for cybersecurity leaders. The discussion begins with defining the scope and importance of vulnerability management, referencing Park Foreman's comprehensive approach beyond mere patching, to include identification, classification, prioritization, remediation, and mitigation of software vulnerabilities. Hardy emphasizes the necessity of a strategic vulnerability management program to prevent exploitations by bad actors, illustrating how vulnerabilities are exploited using tools like ExploitDB, Metasploit, and Shodan. He advises on deploying a variety of scanning tools to uncover different types of vulnerabilities across operating systems, middleware applications, and application libraries. Highlighting the importance of prioritization, Hardy suggests focusing on internet-facing and high-severity vulnerabilities first and discusses establishing service level agreements for timely patching. He also covers optimizing the patching process, the significance of accurate metrics in measuring program effectiveness, and the power of gamification and executive buy-in to enhance security culture. To augment the listener's knowledge and toolkit, Hardy recommends further resources, including OWASP TASM and books on effective vulnerability management.

    Transcripts: https://docs.google.com/document/d/13P8KsbTOZ6b7A7HDngk9Ek9FcS1JpQij

    OWASP Threat and Safeguard Matrix - https://owasp.org/www-project-threat-and-safeguard-matrix/

    Effective Vulnerability Management - https://www.amazon.com/Effective-Vulnerability-Management-Vulnerable-Ecosystem/dp/1394221207

    Chapters

    • 00:00 Introduction
    • 00:56 Understanding Vulnerability Management
    • 02:15 How Bad Actors Exploit Vulnerabilities
    • 04:26 Building a Comprehensive Vulnerability Management Program
    • 08:10 Prioritizing and Remediation of Vulnerabilities
    • 13:09 Optimizing the Patching Process
    • 15:28 Measuring and Improving Vulnerability Management Effectiveness
    • 18:28 Gamifying Vulnerability Management for Better Results
    • 20:38 Securing Executive Buy-In for Enhanced Security
    • 21:15 Conclusion and Further Resources

    #172 - Table Top Exercises Mar 11, 2024
    Show notes

    This episode of CISO Tradecraft, hosted by G Mark Hardy, delves into the concept, significance, and implementation of tabletop exercises in improving organizational security posture. Tabletop exercises are described as invaluable, informal training sessions that simulate hypothetical situations allowing teams to discuss and plan responses, thereby refining incident response plans and protocols. The podcast covers the advantages of conducting these exercises, highlighting their cost-effectiveness and the crucial role they play in crisis preparation and response. It also discusses various aspects of preparing for and executing a successful tabletop exercise, including setting objectives, selecting participants, creating scenarios, and the importance of a follow-up. Additionally, the episode touches on compliance aspects related to SOC 2 and the use of tabletop exercises to expose and address potential organizational weaknesses. The overall message underscores the importance of these exercises in preparing cybersecurity teams for real-world incidents.

    Outline & References:

    https://docs.google.com/document/d/13Qj4MOjPxWz9mhQCDQNBtoQwrXdTeIEf

    Transcripts: https://docs.google.com/document/d/1yfmZALQfkhQCMfp9ao3151P9L2XcEXFm/

    Chapters

    • 00:00 Introduction
    • 00:47 The Importance of Tabletop Exercises
    • 01:53 The Benefits of Tabletop Exercises
    • 03:06 How to Implement Tabletop Exercises
    • 05:30 The Role of Tabletop Exercises in Compliance
    • 08:24 The Participants in Tabletop Exercises
    • 09:25 The Preparation for Tabletop Exercises
    • 16:57 The Execution of Tabletop Exercises
    • 21:58 Understanding Roles and Responsibilities in an Exercise
    • 22:17 The Importance of a Hot Wash Up
    • 23:36 Creating an After Action Report (AAR)
    • 24:06 Implementing an Action Plan
    • 24:34 Example Scenario: Network Administrator's Mistake
    • 25:08 Formulating Targeted Questions for the Scenario
    • 26:36 The Role of Innovation in Tabletop Exercises
    • 27:11 The Connection Between Tabletop Exercises and Compliance
    • 29:18 12 Key Steps to a Successful Exercise
    • 30:43 The Importance of Realistic Scenarios
    • 34:05 The Role of Communication in Crisis Management
    • 37:33 The Impact of Cyber Attacks on Operations
    • 39:57 The Importance of Tabletop Exercises and How to Get Started

    #171 - Navigating Software Supply Chain Security (with Cassie Crossley) Mar 04, 2024
    Show notes

    In this episode of CISO Tradecraft, host G Mark Hardy converses with Cassie Crossley, author of the book on software supply chain security. Hardy explores the importance of cybersecurity, the structure of software supply chains, and the potential risks they pose. Crossley shares her expert insights on different software source codes and the intricacies of secure development life cycle. She highlights the significance of Software Bill of Materials (SBOM) and the challenges in maintaining the integrity of software products. The discussion also covers the concept of counterfeits in the software world, stressing the need for continuous monitoring and a holistic approach towards cybersecurity.

    Link to the Book: https://www.amazon.com/Software-Supply-Chain-Security-End/dp/1098133706?&_encoding=UTF8&tag=-0-0-20&linkCode=ur2

    Transcripts: https://docs.google.com/document/d/1SJS2VzyMS-xLF0vlGIgrnn5cOP8feCV9

    Chapters

    • 00:00 Introduction
    • 01:44 Discussion on Software Supply Chain Security
    • 02:33 Insights into Secure Development Life Cycle
    • 03:20 Understanding the Importance of Supplier Landscape
    • 05:09 The Role of Security in Software Supply Chain
    • 07:29 The Impact of Vulnerabilities in Software Supply Chain
    • 09:06 The Importance of Secure Software Development Life Cycle
    • 14:13 The Role of Frameworks and Standards in Software Supply Chain Security
    • 17:39 Understanding the Importance of Business Continuity Plan
    • 20:53 The Importance of Security in Agile Development
    • 24:01 Understanding OWASP and Secure Coding
    • 24:20 The Importance of API Security
    • 24:50 The Concept of Shift Left in Software Development
    • 25:20 The Role of Culture in Software Development
    • 25:52 Exploring Different Source Code Types
    • 26:19 The Rise of Low Code, No Code Platforms
    • 28:53 The Potential Risks of Generative AI Source Code
    • 34:24 Understanding Software Bill of Materials (SBOM)
    • 41:07 The Challenge of Spotting Counterfeit Software
    • 41:36 The Importance of Integrity Checks in Software Development
    • 45:45 Closing Thoughts and the Importance of Cybersecurity Awareness

    #170 - Responsibility, Accountability, and Authority Feb 26, 2024
    Show notes

    In this episode of CISO Tradecraft, the host, G Mark Hardy, delves into the concepts of responsibility, accountability, and authority. These are considered critical domains in any leadership position but are also specifically applicable in the field of cybersecurity. The host emphasizes the need for a perfect balance between these areas to avoid putting one in a scapegoat position, which is often common for CISOs. Drawing on his military and cybersecurity experiences, he provides insights into how responsibility, accountability, and authority can be perfectly aligned for the efficient execution of duties. He also addresses how these concepts intertwine with various forms of power - positional, coercive, expert, informational, reward, referent, and connection. The host further empathizes with CISOs often put in tricky situations where they are held accountable but lack the authority or resources to execute their roles effectively and provides suggestions for culture change within organizations to overcome these challenges.

    Transcripts: https://docs.google.com/document/d/1S8JIRztM6iaZonGv0qhtWY4vDyBfGhs-/

    Chapters

    • 00:00 Introduction
    • 00:22 Understanding Responsibility, Accountability, and Authority
    • 01:20 The Role of Leadership in Cybersecurity
    • 02:47 Exploring the Concepts of Responsibility, Authority, and Accountability
    • 03:08 Applying Responsibility, Authority, and Accountability to the CISO Role
    • 04:20 The Interplay of Responsibility, Authority, and Accountability
    • 11:57 Understanding Power and Its Forms
    • 12:43 The Impact of Power on Leadership and Influence
    • 24:04 The Role of Connection Power in Today's Digital Age
    • 24:40 Understanding Different Sources of Power
    • 25:13 The Power of Networking and Connections
    • 26:49 The Challenges of Being a CISO
    • 29:19 Understanding the Value of Your Role
    • 33:56 The Importance of Expert Power
    • 37:46 The Consequences of Ignoring Maintenance
    • 43:40 Aligning Responsibility, Accountability, and Authority
    • 44:39 The Importance of Legal Protections for CISOs
    • 45:30 Wrapping Up: Balancing Responsibility, Authority, and Accountability

    #169 - MFA Mishaps Feb 19, 2024
    Show notes

    In this episode of CISO Tradecraft, host G Mark Hardy discusses various mishaps that can occur with Multi-Factor Authentication (MFA) and how these can be exploited by attackers. The talk covers several scenarios such as the misuse of test servers, bypassing of MFA via malicious apps and phishing scams, violation of the Illinois Biometric Information Protection Act by using biometric data without proper consent, and potential future legal restrictions on biometric data usage. G Mark also highlights the significance of correct implementation of MFA to ensure optimum organizational security and how companies can fail to achieve this due to overlooking non-technical issues like legal consent for biometric data collection.

    Transcripts: https://docs.google.com/document/d/1FPCFlFRV1S_5eaFmjp5ByU-FCAzg_1kO

    References:

    • Evil Proxy Attack- https://www.resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web
    • Microsoft Attack - https://www-bleepingcomputer-com.cdn.ampproject.org/c/s/www.bleepingcomputer.com/news/security/microsoft-reveals-how-hackers-breached-its-exchange-online-accounts/amp/
    • Illinois Biometric Law - https://www.ilga.gov/legislation/publicacts/fulltext.asp?Name=095-0994

    Chapters

    • 00:00 Introduction
    • 00:43 Understanding Multi Factor Authentication
    • 01:05 Exploring Different Levels of Authentication
    • 03:30 The Risks of Multi Factor Authentication
    • 03:51 The Importance of Password Management
    • 04:27 Exploring the Use of Trusted Platform Module for Authentication
    • 06:17 Understanding the Difference Between TPM and HSM
    • 09:00 The Challenges of Implementing MFA in Enterprises
    • 11:25 Exploring Real-World MFA Mishaps
    • 15:30 The Risks of Overprivileged Test Systems
    • 17:16 The Importance of Monitoring Non-Production Environments
    • 19:02 Understanding Consent Phishing Scams
    • 30:37 The Legal Implications of Biometric Data Collection
    • 32:24 Conclusion and Final Thoughts

    #168 - Cybersecurity First Principles (with Rick Howard) Feb 12, 2024
    Show notes

    In this episode of CISO Tradecraft, host G Mark Hardy is joined by special guest Rick Howard, Chief Security Officer, Chief Analyst and Senior Fellow at CyberWire. Rick shares his insights on first principles in cybersecurity, discussing how these form the foundations of any cybersecurity strategy. He emphasizes the importance of understanding materiality and integrating the concept of time bound risk assessment to achieve a resilient cybersecurity environment. The episode also delves into the value of Fermi estimates and Bayes algorithm for risk calculation. Amid humor and personal anecdotes, Rick and Mark also reflect on their experiences during 9/11. Rick introduces his book, 'Cybersecurity First Principles', elucidating the rationale behind its conception.

    Link to the Cybersecurity First Principles Book: https://www.amazon.com/Cybersecurity-First-Principles-Strategy-Tactics/dp/B0CBVSX2H2/?&_encoding=UTF8&tag=-0-0-20&linkCode=ur2&linkId=1b3010fb678a109743f1fb564eb6d0fc&camp=1789&creative=9325

    Transcripts: https://docs.google.com/document/d/1y8JPSzpmqDMd-1PZ-MWSqOuxgFTDVvre

    Chapters

    • 00:00 Introduction
    • 02:00 Guest's Career Journey and Achievements
    • 08:49 Discussion on Cybersecurity First Principles
    • 15:27 Understanding Materiality in Cybersecurity
    • 21:56 The Gap Between Security Teams and Business Leaders
    • 22:21 The Importance of Speaking the Language of Business
    • 23:03 The Art of the Elevator Pitch
    • 24:04 The Impact of Cybersecurity on Business Value
    • 25:10 The Importance of a Clear Cybersecurity Strategy
    • 26:04 The Value of Business Fluency in Cybersecurity
    • 27:44 The Role of Risk Calculation in Cybersecurity
    • 29:41 The Power of Estimation in Risk Management
    • 30:33 The Importance of Understanding Business Imperatives
    • 41:25 The Role of Culture and Risk Appetite in Cybersecurity
    • 45:39 The First Principle of Cybersecurity

    #167 - Cybersecurity Apprenticeships (with Craig Barber) Feb 05, 2024
    Show notes

    In this episode of CISO Tradecraft, host G Mark Hardy is joined by guest Craig Barber, the Chief Information Security Officer at SugarCRM. They discuss the increasingly critical topic of cybersecurity apprenticeships and Craig shares his personal journey from technical network engineer to CISO. They delve into the benefits of apprenticeships for both the individual and the organization, drawing parallels with guilds and trade schools of the past and incorporating real-world examples. They also look at the potential challenges and pitfalls of such programs, providing insights for organizations considering creating an apprenticeship scheme. Lastly, they examine the key attributes of successful apprentices and how these contribute to building stronger, more diverse cybersecurity teams.

    Craig Barber's Profile: https://www.linkedin.com/in/craig-barber/

    Transcripts https://docs.google.com/document/d/1J8nrhYCMBSmc0kLBasskBoY2RLIwR7Vb

    Chapters

    • 00:00 Introduction
    • 00:23 Understanding Cybersecurity Apprenticeships
    • 02:43 The Role of Mentorship in Cybersecurity
    • 04:09 The Benefits of Cybersecurity Apprenticeships
    • 07:17 The Evolution of Apprenticeships in the Tech Industry
    • 10:00 The Value of Apprenticeships in Building Loyalty
    • 11:08 The Difference Between Internships and Apprenticeships
    • 15:32 The Role of Apprenticeships in Addressing the Skills Shortage
    • 19:15 The Challenges of Implementing Apprenticeships
    • 26:28 The Future of Cybersecurity Apprenticeships
    • 44:32 Conclusion: The Value of Cybersecurity Apprenticeships

    Previous 1 8 9 10 11 12 27 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights