TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    CISO Tradecraft®

    You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level.

    © Copyright 2025, National Security Corporation. All Rights Reserved

    Advertise

    Copyright: © Copyright 2024 All rights reserved.

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    #116 - A European view of CISO responsibilities (with Michael Krausz) Feb 13, 2023
    Show notes

    In the US we often focus on SOC-2, NIST Special Pubs, and the Cybersecurity Framework. In Europe (and most of the rest of the world), ISO 27001 is the primary standard. ISO concerns itself with policy, practice, and proof, whereas NIST often shows the method to follow. Michael points out that a CISO is responsible for governance, (internal) consulting, and audit. In early stages of growing a security function, a CISO needs to be technically-focused, but as a security department matures, the CISO must be organizationally-focused. Also, to effectively grow your team, first determine what actions need to take place, how much effort it requires, and how often it needs to take place. Then, build an action sheet and collect data for three months. Finally, take that to your executives and document your requirements for more staff.

    Michael Krausz LinkedIn Profile: https://www.linkedin.com/in/michael-krausz-b55862/

    Michael Krausz Website: https://i-s-c.co.at/

    Full Transcript: https://docs.google.com/document/d/13fghym7IWyPvuRANQXUvmv-ulkSj93xv

    Chapters

    • 00:00 Introduction
    • 04:01 Is there a Gap Analysis in ISO 27001?
    • 08:05 Is there a Requirement for ISO Standards?
    • 10:57 What is ISO 27001?
    • 13:11 Is there a Parallel Development between the US and EU?
    • 16:57 Do you want to be a trooper?
    • 21:17 What's the Oldest Operating System?
    • 23:09 Is there a Legacy Operating Systems that you can't get away with?
    • 24:11 The Most Important Class for a CISO
    • 26:33 The Secrets of a Successful CISO
    • 29:30 CISO - I need 6 people period
    • 33:40 What's the Primary Skill Needed in a CISO?
    • 37:41 How to Maximize the Number of FTEs

    #115 - The Business Case for a Global Lead of Field Cybersecurity (with Joye Purser) Feb 06, 2023
    Show notes

    How can cyber best help the sales organization? It's a great thought exercise that we bring on Joye Purser to discuss. Learn from her experience as we go over how cybersecurity is becoming an even closer business partner with the creation of a new important role.

    Full Transcript: https://docs.google.com/document/d/1Shd1Qldb8iKEHBgXJqFez81Iwfpl6JT-/

    Chapters

    • 00:00 Introduction
    • 02:58 How did you marry those two cultures?
    • 06:40 Building a Diverse Workforce
    • 08:23 Is this a new role based on Pain Points?
    • 10:27 Global Lead for Field Cyber Security
    • 15:51 Is the Global Lead for Field Cybersecurity linked to sales numbers?
    • 19:07 Is there a Global Lead for Field Cybersecurity?
    • 24:46 Building Relationships in a Security Leadership Role
    • 27:48 Do you have any lessons learned from your success at Global Management Consulting?
    • 29:33 You need to schedule time to get things done
    • 33:33 What about Due Diligence?
    • 37:36 The Chief Technology Officer, CRO, & CTO

    #114 - One Vendor to Secure Them All Jan 30, 2023
    Show notes

    Did you ever wonder how much security you can implement with a single vendor? We did and were surprised by how much you can do using the Australian Top Eight as a template. We'll bet you can improve your security by using these tips, tools, and techniques that you might not have even known were there.

    Special thanks to our sponsor Praetorian for supporting this episode.

    https://www.praetorian.com/

    Full Transcripts:

    https://docs.google.com/document/d/12HsuOhY9an1QzIw9wOREPMX0pXe5hqkJ

    Helpful Links

    1. Essential 8 https://www.microsoft.com/en-au/business/topic/security/essential-eight
    2. Blocking Macros https://ite8.com.au/the-essential-8/office-macros-explained/
    3. Windows Defender Application Control or WDAC (available from Windows 10 or Server 2016 or newer) previously Windows had App Locker (Windows 7 / 8)
      • https://docs.microsoft.com/en-us/mem/configmgr/protect/deploy-use/use-device-guard-with-configuration-manager
      • https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control
    4. Windows Group Policies
      • https://techexpert.tips/windows/gpo-block-website-url-google-chrome/
      • https://chromeenterprise.google/policies/#SafeBrowsingAllowlistDomains
      • https://data.iana.org/TLD/tlds-alpha-by-domain.txt
      • Software Restriction Policies http://woshub.com/how-to-block-viruses-and-ransomware-using-software-restriction-policies/
      • Blocking websites URL - only allow (.com, .org, .net, edu, .gov, .mil, and the countries you want).
      • Locking down Active Directory https://attack.stealthbits.com/tag/active-directory
    5. File Service Resource Management
      • http://woshub.com/using-fsrm-on-windows-file-server-to-prevent-ransomware/
    6. Enable MFA for RDP
      • https://docs.microsoft.com/en-us/azure/active-directory-domain-services/secure-remote-vm-access
      • https://duo.com/docs/rdp
    7. Enable MFA for SSH
      • https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/auth-ssh
      • https://docs.microsoft.com/en-us/azure/active-directory/devices/howto-vm-sign-in-azure-ad-linux
    8. Windows Controlled Folder Access
      • https://support.microsoft.com/en-

    #113 - SAST Security (with John Steven) Jan 23, 2023
    Show notes

    This episode provides a deep dive into Static Application Security Testing (SAST) tools. Learn how they work, why they don't work as well as you think they will in certain use cases, and find some novel ways apply them to your organization. Special thanks to John Steven for coming on the show to share his expertise.

    Special thanks to our sponsor Praetorian for supporting this episode.

    https://www.praetorian.com/

    Full Transcripts - https://docs.google.com/document/d/1zoA70k78IjqyJky-2u7_-i2jlWke8_cb

    Chapters:

    • 00:00 Introduction
    • 02:51 Source Code Analyzers
    • 04:22 The three bears of Static Analysis
    • 06:01 Do Linters work Better?
    • 08:00 The Value of Full Programming Analysis Tools over Linters
    • 11:30 The Impact of a Developer's Analysis on a Developer Environment
    • 13:05 SAST Testing
    • 15:47 OWASP Benchmarking
    • 19:13 The First Static Analysis Tools
    • 20:53 Can you break up that worry about Automated Testing?
    • 22:44 Using Static Analysis for Defect Discovery
    • 24:18 Using Static Analysis to Improve Web Security
    • 31:37 Using Static Analysis to Drive Cloud Security
    • 33:15 The Second Thing to Look Out for When Choosing a Static Analysis Tool
    • 34:55 Using Static Analysis to Build a Vulnerability Management Practice
    • 37:35 Can you use Static Analysis to Find Insider Threat?

    #112 - Attack Surface Management (with Richard Ford) Jan 17, 2023
    Show notes

    How do you defend against automated attacks in an era of ChatGPT-formulated malware, coordinated nation-state actors, and a host of disgruntled laid-off security professionals? Want to find your vulnerabilities faster than the bad actors do? Come listen to Richard Ford to learn how to apply best practices in attack surface management and defend your crown jewels.

    Special thanks to our sponsor Praetorian for supporting this episode.

    Full Transcripts - https://docs.google.com/document/d/18QyrN-7V91nxOyRQ0KsNeJU0-k-bTlqj

    Chapters:

    • 00:00 Introduction
    • 04:22 The Impact of Continuous Attack Surface Mapping on Security Responses
    • 07:48 What's the Difference between a CTO and a CIO?
    • 10:24 What attracted you to the problem space?
    • 12:53 Is the Attack Surface really exposed?
    • 16:12 Shadow IT - The Unknown Unknowns that could Bite You
    • 19:56 Is there a Shadow IT problem?
    • 23:24 How to get management on board with Shadow IT?
    • 26:38 Building an Attack Surface Management Program
    • 29:57 You Get What You Measure, Right?
    • 33:27 Do I Have Vulnerable Assets?
    • 39:24 Attack Surface Management

    #111 - Leading with Style Jan 09, 2023
    Show notes

    Have you ever wanted to be like Neo in "The Matrix" and learn things like Kung Fu in just a few minutes? Well on today's episode, we try to do just that by cramming powerful leadership concepts into your head in just 45 minutes. So sit back, relax, and enjoy CISO Tradecraft.

    Show Notes with Pictures & References:

    https://docs.google.com/document/d/1z5FwVwYlNiJlevQXP9IK48Z5kYqG-Ee_/edit?usp=sharing&ouid=104989998442085477687&rtpof=true&sd=true

    Full Transcript: https://docs.google.com/document/d/11iTdKRxtg1UYiQeUn-mdgM7zKqafTq34/edit?usp=sharing&ouid=104989998442085477687&rtpof=true&sd=true


    #110 - CISO Predictions for 2023 Jan 02, 2023
    Show notes

    Want to know CISO Tradecraft's Top 10 cyber security predictions for 2023? Listen to the episode to learn more about:

    1. Proactive Identity Management = Automated Provisioning of Access + Minimizing Digital Blast Radius
    2. Convergence of Security Tools
    3. Collaboration Technology
    4. Evolution of the Endpoint (Chromebooks or Browser Isolation)
    5. Chatbots
    6. Vague and unclear cyber laws
    7. CISO liability increases
    8. Umbrella IT general controls mapping
    9. Companies will be less truthful during 3rd party questionnaires
    10. Cyber defense will become more difficult because of people

    Be sure to also check out G Mark Hardy's annual ISACA talk at http://isaca-cmc.org/

    Link to full transcripts of the podcast can be found here: https://docs.google.com/document/d/1RkrtkuunBn-qaU-Y9HvgHJzAKoIIszcW/edit?usp=sharing&ouid=104989998442085477687&rtpof=true&sd=true


    #109 - The Right Stuff Dec 19, 2022
    Show notes

    Success leaves clues, but sometimes we limit ourselves by only looking close by for them. This week, we pondered what business skills are essential for a successful CISO, and then extended the search to some non-traditional sources to find some very relevant advice. Take the time to listen and do a self-examination (you don't have to submit for a grade :) and see where you could boost your skills portfolio to increase your success as a security leader. Some of the essential skills we discuss on this episode of CISO Tradecraft are:

    • Be a leader
    • Manage money and resources
    • Differentiate yourself and your message
    • Communicate with clarity and emphasis
    • Delegate and hold subordinates accountable
    • Build a personal network
    • Mentor your team
    • Be adaptable
    • Be sensitive to cultural and political issues
    • Watch the details and ensure your management makes informed risk-based decisions &
    • Know your limitations

    We thank our sponsor Nucleus Security for supporting this episode

    Full Transcript: https://docs.google.com/document/d/1C357cX_4wKTRmhRUsGh_2d9vIMX5LspL/

    Show links:

    https://www.smallbusiness.wa.gov.au/starting-and-growing/essential-business-skills

    https://cisotradecraft.podbean.com/e/108-budgeting-for-cisos-with-nick-vigier/

    https://nativeintelligence.com/

    https://github.com/cisotradecraft/Podcast#business-management--leadership

    https://www.ef.com/wwen/blog/efacademyblog/skills-for-success/

    https://www.criticalthinking.org/pages/defining-critical-thinking/766

    https://your.yale.edu/learn-and-grow-what-adaptability-workplace

    https://openai.com/blog/chatgpt/

    https://openai.com/dall-e-2/


    #108 - Show Me The Money (with Nick Vigier) Dec 12, 2022
    Show notes

    There's a lot of things you need to know as a CISO, but one of the things least taught is budgeting best practices. On today's episode, CISO Nick Vigier stops by to share his lessons learned on the topic. His conversations focus on spends vs investments. Remember spends = overhead, whereas investments = growth. Here's a great point.

    [10:00] There are opportunities that we have to frame some of these things as investments versus framing them as risk mitigations. And so one of the mantras or things that I like to think about is the business has a limited appetite for risk management, but they have infinite appetite for profits and making money.

    So if you're able to frame them as how they're actually going to help accelerate the business or improve the business that brings the CEO and the CFO along on the journey, that you're not just there to lock the doors, you might actually be there to help put another floor on the building and that's a very different conversation.

    We also thank our sponsor Nucleus Security for supporting this episode.

    Full Transcript: https://docs.google.com/document/d/1nURiml3BJFnszFRA8qov1CgO_VkDFaCY


    #106 - How to Win Your First CISO Role Nov 28, 2022
    Show notes

    Are You Ready To Win Your First CISO role? Apply these techniques into your resume and interview process so both recruiters and hiring managers will offer you the job. This show focuses on:

    1. Highlighting the Different Types of CISO Roles
    2. Showing how to progress from a Senior Director Role into a Fortune 100 CISO
    3. Resume Tricks and Tips that get you noticed by recruiters
    4. How to have a great interview with a recruiter
    5. What Hiring Managers want to see from CISOs during their interviews

    Please note the full show transcript can be found here https://docs.google.com/document/d/18Feg4eXbezHVPiNQ9qO6Pdht3P0eQ5nn


    Previous 1 14 15 16 17 18 27 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights