You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level.
© Copyright 2025, National Security Corporation. All Rights Reserved
php/* */ ?>
You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level.
© Copyright 2025, National Security Corporation. All Rights Reserved
Copyright: © Copyright 2024 All rights reserved.
This episode of CISO Tradecraft is all about IPv6, featuring Joe Klein. IPv6 is becoming the dominant protocol on the Internet, and CISOs should understand the implications of how their enterprise is potentially vulnerable to attacks that may come from that vector, as well as be aware of defenses that may originate from an effective IPv6 deployment. This broadcast will cover the business cases for IPv6, the technical differences between IPv4 and IPv6, and the security implications of implementing this protocol correctly and incorrectly.
On this episode of CISO Tradecraft, you can learn how to build an Application Security program.
We also recommend reading the Microsoft Security Developer Life Cycle Practices Link
For more great ideas on setting up an application security program please read this amazing guide from WhiteHat Security Link
If you would like to improve cloud security scanning by automating Infrastructure as Code checks, then please check out Indeni CloudRail Link
What is measured gets done. However before you measure you need to think about how best to measure. On this episode of CISO Tradecraft, we provide you new insights into optimizing metrics that matter.
What is a Metric?
Metrics drive outcomes. Before picking a metric consider the following:
When you report metrics highlight three things:
Goals or Metrics should be SMART:
For a helpful list of metrics that you might consider please check out the following list from Security Scorecard Link
Thank you again to our sponsor CyberArk, please check out their CISO Reports.
On this episode of CISO Tradecraft, you can learn the 10 steps to Incident Response Planning:
To learn more about Incident Response Planning, CISO Tradecraft recommends reading this helpful document from the American Public Power Association
If you would like to automate security reviews of infrastructure-as-code, then please check out Indeni CloudRail Link
Special Thanks to our podcast Sponsor, CyberArk.
Experienced CISOs know that it's not a matter of if, but when. Incidents happen, and there is an established response strategy nicknamed PICERL that works:
If we "shift left" with our incident planning, we can minimize our organizational risk -- thorough preparation, including establishing an environment of least privilege, significantly increases the challenge for an attacker, buys us time to identify early, and limits the damage potential from an incident.
This episode features Bryan Murphy, the Incident Response team leader at CyberArk. His insights from managing dozens of responses are invaluable, and they are now yours through this special episode
On this episode of CISO Tradecraft, you can learn about the new Executive Order on Improving the Nation's Cyber Security. The episode provides a brief background on three security incidents which have influenced the Biden administration:
The episode then overviews the various sections of the new Executive Order:
Thanks to CyberArk for sponsoring this episode. Please check out CyberArk's new conference
This episode is sponsored by Indeni.
On this episode of CISO Tradecraft, G Mark Hardy discusses with Yoni Leitersdorf (CEO and CISO of Indeni) the risks which can occur in a cloud environment after it has been provisioned. Essentially it's quite common for organizations to change their cloud environment from what was declared in a Terraform or Cloud Formation Script. These unapproved cloud changes or Cloud Drift often create harmful misconfigurations and have the potential to create data loss events.
The podcast discusses the pros and cons of two key approaches to solve the Cloud Drift problem:
The podcast features Yoni Leitersdorf. Yoni founded a company (Indeni) to address Cloud Drift and discusses the business point of view of why this is a critical concern for the business. If you would like to learn more about what Yoni is working on please check out Indeni
Yoni Leitersdorf can also be found on: LinkedIn
Identity is the New Perimeter. On this episode of CISO Tradecraft you will increase your understanding of Identity and Access Management. Key topics include:
Have you ever heard a vendor has software features such as Artificial Intelligence (AI) or Machine Learning (ML)? What does that mean? On this episode we answer those questions so you know when vendors are full of it.
References
Today, CISO Tradecraft hosts a 5 minute discussion to talk about reflection. The concept is Roses, Buds, and Thorns. It’s an exercise designed to identify opportunities to make positive change.
If you would like to learn more please check out the article from MITRE
We would love to hear your feedback here.
Thank you, CISO Tradecraft