CISO Tradecraft®

CISO Tradecraft®

G Mark Hardy & Ross Young
Šalis Jungtinės Valstijos
Žanrai Technologija
Kalba EN
Epizodų 302
Naujausias 21.09.2026

CISO Tradecraft is a cybersecurity podcast focused on helping professionals advance their careers and develop the skills needed to reach executive-level roles. It covers practical tradecraft, leadership, and strategies for chief information security officers and aspiring security leaders. Hosted by G Mark Hardy and Ross Young, the show aims to close the skills gap rather than simply waiting for years of experience. Episodes provide actionable advice for taking cybersecurity skills to the executive level.

Epizodai

  • Security Awareness Tips for 2026 - #302 21.09.2026 42min
    In this episode, we reveal the biggest security awareness mistakes and the creative ways to make cybersecurity training actually fun in 2026. From AI-powered phishing and token theft to stronger MFA and gamified training, There are ideas every security leader should steal.Watch now and level up your security awareness game!
  • How to Create a Leadership Culture - #301 14.09.2026 43min
    Most CISOs spend years learning cybersecurity.Almost nobody teaches them how to build a culture people actually want to be part of.In this episode of CISO Tradecraft, G. Mark Hardy and Ross Young break down the leadership lessons that separate average security organizations from world-class ones.You’ll learn how to:Build a security team people WANT to joinDevelop your employees into future CISOsReward behavior that actually changes cultureCommunicate like an executiveSpot when your company may NEVER promote you to CISOPrevent burnout before your best people leaveBuild trust across the businessCreate a culture of excellence, accountability, and curiosityRoss also shares how he turned phishing awareness into a company competition, complete with trophies, CEO recognition, and brisket parties.Because great cybersecurity leadership isn't just about stopping hackers.It's about building an organization where great people can do their best work.What’s the ONE leadership rule every CISO should follow?Subscribe to CISO Tradecraft for practical lessons on cybersecurity leadership, strategy, risk, and becoming a more effective CISO.Template for Command Philosophy: https://www.gmarkhardy.com/Navy_Articles/NRA-0306%20Template%20for%20a%20Command%20Philosophy.pdf
  • CISO Health and Accountability Dialogue - #300 07.09.2026 15min
    The biggest threat to a CISO might not be ransomware, it might be burnout. In this episode, G. Mark Hardy brings on We Hack Health to reveal why brilliant security leaders are sacrificing their health, how accountability can reverse the damage, and the one rule every CISO should follow: Never miss twice. Watch this before your career costs you everything.Link to CruiseConhttps://cruisecon.com/events/cruisecon-privacy-ai-2026/Use code: CISOTRADECRAFT10 for a 10% discount
  • Claude Code Is INSANE, But Is It Safe? - #299 31.08.2026 45min
    Claude Code Is INSANE… But Is It Safe?AI coding just went from “autocomplete my code” to “give me the entire repository and let me run the company.”In this episode of CISO Tradecraft, G Mark Hardy and Ross Young break down what Claude Code can actually do, and the security implications that come with it.Claude Code can read entire codebases, create and edit multiple files, run commands, execute tests, and operate like an AI developer sitting directly inside your environment.But there’s a catch…Every token costs money. And every permission creates risk.We break down:🔥 Tokenomics — How to get dramatically more AI coding for your dollar 🔥 PRDs — Why you should use powerful models to THINK before cheaper models BUILD 🔥 Security Risks — What happens when an AI agent can execute commands and modify your environment? 🔥 AI Licenses — Individual vs. enterprise and what CISOs need to worry about 🔥 Privacy & Regulated Data — When you may need offline or open-weight models 🔥 Harnesses — The policy-driven guardrails that can move security WAY earlier in the development process 🔥 MCP — How AI agents can connect to tools, systems, and data… and why permissions become a massive security issue 🔥 Agents & Skills — Serial vs. parallel agents, prompts, context, commands, hooks, and Markdown-based skills 🔥 Threat Modeling AI — Why you need to start threat modeling the prompts AND the toolsThe big question isn't:“Can AI write code?”It absolutely can.The question is:“What happens when we give AI the keys to the kingdom?”If you're a CISO, security leader, developer, or anyone trying to understand where agentic AI coding is heading, this episode is for you.🎙️ Subscribe to CISO Tradecraft for more unfiltered conversations about cybersecurity, AI, leadership, and the future of the CISO.Check out the Harness that Ross is building: https://github.com/Clear-Capabilities/agentic-security
  • VCISO Tradecraft | Carlota Sage - #298 25.08.2026 42min
    Most cybersecurity advice is built for massive enterprises.But what happens when you're a small or medium-sized business and you don't have a 200-person security team… or a massive budget?In this episode, Mark Hardy sits down with vCISO Carlota Sage to break down what actually works.Carlota shares lessons from her time at FireEye during its explosive growth and the Mandiant acquisition—and why being a great security leader isn't just about knowing cybersecurity.It's about IT fundamentals. Influence. Emotional intelligence. And knowing how to lead people.We also dive into:Why simply saying "thank you" can transform your security culture 💰 How cybersecurity can become sales enablement and revenue protection 📈 Why security teams should work directly with sales and finance 🔒 Why compliance isn't security—but ISO 27001 and PCI DSS can still be incredibly valuable for smaller companies 🤖 How AI is creating a massive new attack surface 🕵️ The growing risk of sensitive data leaking into AI tools 💸 Why the real cost of AI isn't just the subscription price 🎯 Who should be accountable when AI goes wrongThe BIG takeaway?You don't need to be a Fortune 500 company to build a strong security program.But you do need to understand the business, influence people, protect revenue, and help your organization use technology without creating a disaster in the process.Watch now and let us know in the comments:What's the biggest cybersecurity challenge facing small and medium-sized businesses right now? 👇
  • AI's Biggest Security Problem | Jeff Spear - #297 17.08.2026 40min
    AI can change your network in seconds… but your security approvals still take DAYS. In this episode, Tufin CISO Jeffrey Spear reveals how CISOs can use automation and AI without accidentally scaling security mistakes at machine speed. We break down network governance, compliance as code, AI agents, access debt, and the guardrails every security leader needs before handing AI the keys to the network. Automate the right way or build a faster way to be wrong.Get Your Network Exposure Assessment https://explore.tufin.com/assessmentBig thanks to our sponsor Tufin.
  • AI Is Breaking Out and Cybersecurity Isn’t Ready | John Strand - #296 10.08.2026 44min
    What happens when AI stops behaving like a tool, and starts operating beyond the boundaries we gave it? Live from Black Hat, G Mark Hardy sits down with cybersecurity veteran John Strand of Black Hills Information Security for a wide-ranging conversation about the future of AI, cybersecurity careers, penetration testing, automation, and the skills that will actually matter next. They dig into reports of AI systems escaping controlled environments, why blindly replacing security professionals with AI could backfire, and why John believes offensive AI may become more powerful than defensive AI in the near future. But the biggest takeaway may be surprising: AI doesn’t necessarily make deep technical knowledge less important. It may make it more valuable than ever. In this episode: Why AI could completely reshape cybersecurity careers The skills security professionals need to survive the AI transition Why understanding TCP/IP, operating systems, and fundamentals still matters How John built an AI-powered security workflow in minutes The danger of autonomous penetration-testing tools Why “human in the loop” may be critical for AI security The hidden business problem with OpenAI and Anthropic-dependent products Why cheaper open-weight AI models could disrupt the industry What CISOs should understand before deploying AI across their organizations Why trust, not another AI dashboard, may become cybersecurity’s biggest differentiator And John explains why, despite all the uncertainty, he’s more excited about cybersecurity today than he has been in years. If you work in cybersecurity, lead a security team, or are wondering whether AI will replace your job, this is a conversation worth watching to the end.
  • Is AI Leaking Your Company's Trade Secrets | Lee Kim - #295 03.08.2026 45min
    What Every CISO Needs to Know Before AI Leaks Your Company's Crown Jewels Your AI policy won't save you if your trade secrets walk out the door. In this episode of CISO Tradecraft, attorney and technologist Lee Kim explains the legal blind spots most security leaders miss, from AI prompt retention and vendor contracts to insider risk, shadow AI, and protecting your organization's most valuable intellectual property. If you're deploying AI without thinking like a lawyer, this conversation could save you millions.Lee Kim's LinkedIn - https://www.linkedin.com/in/leekim/
  • Learning from the Hugging Face Incident | Gadi Evron - #294 27.07.2026 48min
    In this CISO Tradecraft episode, host G Mark Hardy and guest Gadi Evron discuss a recent incident involving OpenAI model testing in an “exploit gym,” where an agent escaped its sandbox, attempted to access Hugging Face, created new exploits, stole credentials, and generated high-volume, unusual activity that initially blended into background noise. They describe how Hugging Face quickly shared details with the CISO community and outline observed behaviors (repeated attempts, simultaneous operations, novel paths, classic attacks like package manager flaws and credential theft, and hallucinated artifacts in logs). Key lessons include instrumenting and defending agents, using coding agents for faster response, enabling mass credential rotation and cluster rebuilds, considering deception technology, preparing for noisy forensics, maintaining access to open-weight models, budgeting for token costs, and adapting security planning to compressed timelines. CISO Retreat - https://www.cisotradecraft.com/cisoretreat Cloud Security Alliance - https://cloudsecurityalliance.org/ CSides - https://luma.com/jf8ej87e Hugging Face Analysis on ChatGPT - https://www.linkedin.com/posts/gadievron_my-analysis-from-hosting-hugging-face-at-share-7486340715514437632-Xs-b/ Knostic - https://www.knostic.ai/ Unprompted - https://unpromptedcon.org/
  • Legal Developments Every CISO Needs to Know | Larry Dietz - #293 20.07.2026 41min
    Three major legal changes. One question every CISO should be asking: Is your cybersecurity program ready?Congress let a key FISA surveillance authority expire. The Supreme Court raised the bar on geofence warrants. The Department of Defense paused mandatory CMMC Level 2 certifications.At first glance, these seem like unrelated legal headlines. In reality, they all point to the same challenge: cybersecurity leaders must understand how changing laws affect data access, privacy, compliance, and personal liability.In this episode of CISO Tradecraft, host G. Mark Hardy sits down with attorney and cybersecurity expert Larry Dietz to break down what these legal developments actually mean for CISOs, not from a political perspective, but from a practical leadership perspective.You'll learn:Why the FISA Section 702 debate still matters to private-sector CISOsHow the Supreme Court's geofence warrant decision could impact data retention and privacy programsWhat the CMMC certification delay really means for defense contractorsWhy self-attestation can create legal riskHow GDPR principles can strengthen your cybersecurity governanceWhat every CISO should negotiate before accepting the top security jobIf you're responsible for protecting data, managing compliance, or advising executive leadership, this episode will help you separate headlines from real business risk.Subscribe for weekly insights that help cybersecurity leaders become more effective.
  • The Business Risk Playbook CISOs Use to Win - #292 13.07.2026 41min
    What separates great CISOs from everyone else? It isn't knowing more about CVEs, ransomware, or the latest security tools. It's understanding the business. In this episode of CISO Tradecraft, Ross Young and G Mark Hardy reveal why many cybersecurity leaders spend too much time protecting systems and not enough time protecting the capabilities that generate revenue, keep operations running, and create shareholder value. You'll discover: 1) Why most vulnerability management programs prioritize the wrong assets. 2) The six business capabilities every CISO should understand before making security decisions. 3) How executive leaders evaluate cyber risk differently than security teams. 4) A practical framework for aligning cybersecurity investments with business priorities. 5) Why traditional third-party risk questionnaires often fail—and the questions that actually predict ransomware risk. 6) Lessons learned from real-world breaches, mergers & acquisitions, business resilience, and executive decision making. Free Resources Mentioned • Ransomware Risk Assessment Questionnaire - https://drive.google.com/file/d/1L4spXwrB7nFgdSP5at2uJfFKvG_7ppmz/ • Mission-Critical Business Capability Framework - https://docs.google.com/presentation/d/1zHjxcJXvAkJNQKXCVbVoR7yzexD3KKEu
  • The CISO Mind Map Has Evolved for the AI Era - #291 06.07.2026 41min
    How has the role of the CISO changed over the last 15 years? In this episode of CISO Tradecraft, G. Mark Hardy interviews Rafeeq Rehman, creator of the CISO Mind Map, to discuss its latest update and the biggest challenges facing cybersecurity leaders today. You'll learn: Why the CISO Mind Map was updated after 15 years How AI security is reshaping cybersecurity leadership Why the remote work category was removed How a RACI matrix helps CISOs delegate while staying accountable Why consolidating security tools reduces complexity and risk How to support your team's mental health in a high-stress industry What tomorrow's cybersecurity leaders need to succeed Whether you're an aspiring CISO or an experienced security executive, this episode provides practical insights to help you lead more effectively in the AI era. Link to the Mind Map - https://rafeeqrehman.com/2026/04/11/ciso-mindmap-2026-what-do-infosec-professionals-really-do/
  • Harvest Now, Decrypt Later | Marcus Sachs - #290 29.06.2026 41min
    Nation-state adversaries are vacuuming up encrypted traffic today, waiting for quantum computers to decrypt it tomorrow. This attack strategy, "Harvest Now, Decrypt Later," isn't theoretical. It's happening right now.G Mark Hardy sits down with Marcus Sachs (former White House cyber advisor, CSO of NERC, now SVP and Chief Engineer at CIS) to break down two executive orders just signed by the White House on post-quantum cryptography and what every security leader needs to do before the clock runs out.What you'll learn:Why TLS, VPNs, and PKI are your most urgent exposureThe Harvest Now, Decrypt Later threat model and what it means for your data retention policiesHow to build a Cryptographic Bill of Materials (CBOM)What cryptographic agility means and why hard-coded crypto is a ticking time bombLessons from Y2K that apply directly to the quantum migrationYou can't name a date certain. But your adversaries are already running the clock.Links, NIST resources, and both executive orders in the show notes.https://www.nist.gov/cybersecurity-and-privacy/what-post-quantum-cryptographyhttps://www.nist.gov/pqc
  • #289 - What's the Best Career Move After Being a CISO? (with Gary Hayslip) 22.06.2026 43min
    On this episode of CISO Tradecraft, host G Mark Hardy talks with Gary Hayslip about cybersecurity career growth beyond the traditional CISO “apex,” drawing on Hayslip’s 25+ years across military service, US Navy civil service, the City of San Diego as its first CISO, Webroot (CISO/CIO), SoftBank (including cyber and physical security), and most recently a field CISO role before being laid off. They discuss how the CISO role is evolving into merged executive positions (technology, risk, and AI), why continuous learning is essential as security changes rapidly, and why humans remain accountable even as AI reshapes teams. Hayslip outlines alternative paths like field CISO, data center security leadership, and VC/PE operating partner roles, and shares practical ways organizations used AI to speed legal review and automate security reporting while highlighting cost, risk, and workforce concerns.
  • #288 - How to Break Into Cybersecurity Through GRC (with Steve McMichael) 15.06.2026 39min
    In this CISO Tradecraft episode, host G Mark Hardy interviews Steve McMichael, author of "How to Break into GRC: Mindset, Methods, and Skills," about entering cybersecurity through governance, risk, and compliance. McMichael shares his transition from accounting and explains GRC’s role as decision support and the interface between business and technical teams, breaking down governance, risk management, and compliance (including audits and third-party/supply-chain assurance). They discuss misconceptions that GRC is “just paperwork,” barriers like imposter syndrome, and strategies such as building T-shaped skills, targeting about 20% technical depth across domains, and developing credibility through a deep specialty. McMichael also describes an immersion mindset driven by emotional engagement, and showcases an open-source NIST Cybersecurity Framework Profile Assessment Database project on GitHub to help newcomers build skills and portfolio contributions.
  • #287 - Cybersecurity Insights You'll Want to Hear (with Michael Hammer) 08.06.2026 45min
    Want to move from "security expert" to "trusted business leader"?Join G. Mark Hardy and Michael Hammer. The mind behind the core of DMARC, for 40 years of hard-won wisdom on navigating the CISO role, This episode is a masterclass in evolving from a technical gatekeeper to a strategic influencer who changes the environment,.Inside this episode:Modern Email Security: Why DMARC and SPF aren't "set and forget" tools and how to stop "cousin domain" attacks,.The 30-Minute Audit: Use the "Turn the Rocks Over" method to vet any vendor’s security posture in minutes.Risk vs. Ownership: Why you must ensure the executive team makes informed risk decisions, and why you should get them in writing.The AI Storm: How Mythos AI is accelerating the disclosure of years of hidden code vulnerabilities,.Stop being a "compliance tax" and start protecting revenue. Watch now to learn how to build a true security culture
  • #286 - AI-Native Security (with Nishant Doshi & Saro Subbiah) 01.06.2026 45min
    What if your next breach isn't caused by a human... but by an AI agent acting exactly as instructed?Cyberhaven's CEO (Nishant Doshi) and SVP of Engineering (Saro Subbiah) reveal why AI is a true zero-to-one shift, why every employee is building agents, and why traditional security controls are struggling to keep up with machine-speed workflows.The most interesting question for CISOs isn't whether AI will be adopted, it's which security control breaks first when thousands of human-plus-agent workflows start operating across your enterprise?Watch the episode and weigh in: What do you believe will be the first major failure point of enterprise AI adoption, identity, code review, third-party dependencies, data security, audit trails, or something else entirely?Big thanks to our Sponsor Cyberhaven -https://www.cyberhaven.com/product
  • #285 - Passwordless Authentication (with Nishant Kaushik) 25.05.2026 42min
    In this discussion, G. Mark Hardy and Nishant Kaushik explore the necessity of moving beyond traditional passwords, which they define as the original sin of cybersecurity due to their vulnerability to credential stuffing and phishing attacks. Kaushik explains that the FIDO Alliance promotes a passwordless future by replacing shared secrets with asymmetric cryptography, utilizing private keys stored on smartphones or hardware tokens like YubiKeys to ensure phishing-resistant authentication. The conversation highlights that identity is the new perimeter, shifting the focus from human-memorized codes to biometric verification and device-bound passkeys that verify user presence. Ultimately, the experts warn that a secure transition must include robust account recovery flows, as failing to secure the "back door" renders even the most advanced cryptographic-based authentication vulnerable to exploitation.FIDO Alliance - https://fidoalliance.org/
  • #284 - Lessons Learned from SQL Slammer to AI Agents (with Aaron Turner) 18.05.2026 45min
    What can today’s CISOs learn from the chaos of Code Red and SQL Slammer?In this episode, G Mark Hardy interviews Aaron Turner about what it was like responding inside Microsoft during two of the most infamous cyber outbreaks in history.Aaron shares firsthand stories from the era when SQL Slammer infected at least 75,000 systems in roughly 10 minutes, exposing massive gaps in patch management, security QA, firewall design, and enterprise readiness. He explains how Microsoft’s early security culture operated, how major incidents and source-code theft forced change, and why many of the same mistakes are now reappearing in enterprise AI adoption.The conversation connects the lessons of Code Red and Slammer directly to today’s AI security challenges, including:Unauthenticated MCP servers and weak authorization modelsAI accelerating exploit development and vulnerability discoveryWhy the traditional “patching game” no longer scalesThe growing importance of identity security, ITDR, SASE, and developer controlsHow CISOs should think about technical debt and legacy modernizationWhy serverless and cloud-native architectures may become security necessitiesIf you’re a CISO, deputy CISO, security architect, or aspiring security leader navigating the risks of AI-driven attacks, this episode provides practical lessons from one of the most important eras in cybersecurity history and why those lessons matter even more today.Aaron Turner's Linkedin - https://www.linkedin.com/in/aaronrturner/
  • #283 - Leadership Lessons and the Art of the Performance (with Chris Brogan) 11.05.2026 47min
    In this episode of the CISO Tradecraft podcast, host G Mark Hardy interviews early tech adopter Chris Brogan to explore the intersection of high-performance leadership and effective communication. Drawing from his interviews with Navy SEALs and his tenure as a Chief of Staff, Brogan emphasizes that leadership is essentially the management of options and the cultivation of repetitive training to build a reliable team base. The discussion highlights the necessity of aligning staff roles with business needs, which sometimes requires the difficult but professional decision to let individuals go when they no longer fit the objective. Both experts stress that fully qualifying personnel for their next level of responsibility is a vital duty for any leader aiming for organizational excellence. Ultimately, the conversation advocates for authenticity, a willingness to fail forward, and the use of technology to foster genuine human interaction.Chris Brogan's LinkedIn - https://www.linkedin.com/in/cbrogan/

Populiari šalyje

Ši tinklalaidė taip pat patenka į šių šalių tinklalaidžių topus.