You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level.
© Copyright 2025, National Security Corporation. All Rights Reserved
php/*
You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level.
© Copyright 2025, National Security Corporation. All Rights Reserved
Copyright: © Copyright 2024 All rights reserved.
This episode features Rafeeq Rehman. He discusses the need for a CISO Mindmap and 6 Focus Areas for 2022-2023:
1. Re-evaluate ransomware defenses, detection and response capabilities, perform a business impact analysis and identify critical processes, applications and data.
2. Reduce/consolidate security tools/technologies and vendors. More tools don’t necessarily reduce risk but do add the need for maintaining expertise on security teams.
3. To serve your business better, train staff on business acumen, value creation, influencing and human experience.
4. Take an inventory of open source software (standalone and libraries) and make it part of your vulnerability management program.
5. Build team expertise in technology fields including machine learning (ML) models, model training, API security, service mesh, containers, DevSecOps.
6. Maintain a centralized risk register. Even better: integrate into your enterprise risk management program. Track risk for technology, insiders, processes, third parties, compliance and skill gaps.
Links:
On this episode of CISO Tradecraft, we feature Helen Patton.
Helen shares many of her career experiences working across JP Morgan, The Ohio State University, and now Cisco.
-Is technical acumen needed for CISOs?
-Surviving organizational politics
(34:45) Helen discusses The Fab 5 Security Outcomes study.
Volume 1 Study - Link
Volume 2 Study - Link
On this episode of CISO Tradecraft we feature Robin Dreeke from People Formula. Robin was the former head of the FBI Counterintelligence Behavioral Analysis Program and has an amazing background in learning how individuals think, build trust, and communicate. Robin highlights 4 Pillars of Communicating:
To learn more about Robin's way of thinking you can check out his podcast and books:
This episode is sponsored by Varonis. You can learn more on how to reduce your ransomware radius by performing a free ransomware readiness assessment Link
On this episode, Sounil Yu continues his discussion about his new book ("Cyber Defense Matrix"). Listen to learn more about:
This episode is sponsored by Varonis. You can learn more on how to reduce your ransomware radius by performing a free ransomware readiness assessment Link
This episode of CISO Tradecraft has Sounil Yu talk about his new book, "Cyber Defense Matrix: The Essential Guide to Navigating the Cybersecurity Landscape". Sounil reviews the Cyber Defense Matrix in depth. We discuss how the Cyber Defense Matrix can be used for:
You can purchase Sounil's new book here Link
On this episode of CISO Tradecraft, John Hellickson from Coalfire talks about his career as a CISO. Listen and learn about:
A respected journalist focusing on cybersecurity and our community of people for over 25 years, Deb Radcliff remains a trusted information source who checks and double-checks her sources before publication -- a refreshing change to the low signal - high noise world of social media. In this episode, we discuss where CISOs might turn for accurate information, how the industry has evolved in complexity, and take a look at the first of three fictional novels she's writing about a future world where hackers take on an oppressive digital state. What is really interesting is her explanation of how she went from book idea to published reality.
Breaking Backbones Information is Power may be purchased from the following Amazon Link
On this Episode of CISO Tradecraft we talk about the Top 10 areas of concern for the C Suite about Ransomware. Note you can read the full ISC2 Study here (Link).
Cybersecurity professionals should keep the following golden rules in mind when communicating with the C-suite about ransomware.
On this episode of CISO Tradecraft, Christian Hyatt from risk3sixty stops by to discuss the 3 major Business Objectives for CISOs:
He also discusses the five CISO Archetypes.
References: The 5 CISO Archetypes Book Link
Designing the CISO Role Link
Chances are your organization has information that someone else wants. If it's another nation state, their methods may not be friendly or even legal. In this episode we address assessing risk, known "bad" actors, information targets, exfiltration, cyber security models, what the federal government is doing for contractors, and response strategies. Listen now so you don't become a statistic later.
References:
https://www.fbi.gov/file-repository/china-exec-summary-risk-to-corporate-america-2019.pdf
https://nhglobalpartners.com/made-in-china-2025/
https://www.cybintsolutions.com/cyber-security-facts-stats/
http://www.secretservice.gov/ntac/final_it_sector_2008_0109.pdf
http://www.secretservice.gov/ntac/final_government_sector2008_0109.pdf
CIS Controls v8.0, Center for Internet Security, May 2021, https://www.cisecurity.org