The Tea on Cybersecurity

The Tea on Cybersecurity

Trava Security
Negara Amerika Syarikat
Genre Teknologi
Bahasa EN
Episod 58
Terkini 27.01.2026

Cybersecurity is a term we hear constantly, but many don't truly understand what it involves. This podcast strips away the confusing jargon to explain security and compliance in plain, actionable language. Each episode offers practical insights tailored for SaaS startups and small to medium-sized businesses beginning their cybersecurity journey. Episodes are kept short, typically 15–30 minutes, delivering essential facts without unnecessary filler.

Episod

  • Key Takeaways from Season 5 of The Tea on Cybersecurity 27.01.2026 9min
    On Season 5 of The Tea on Cybersecurity, one thing became clear: security is not a one-and-done deal. It’s a continuous journey.In this episode, host Jara Rowe wraps up the season by highlighting the key takeaways and tackling the biggest myths and misconceptions in cybersecurity and compliance. She also discusses how businesses can future-proof their security posture by focusing on Continuous Threat Exposure Management (CTEM).Tune in to hear actionable advice for 2026 and beyond to keep your business secure as cybersecurity keeps evolving. Key takeaways:The importance of continuous security and complianceHow to keep up with changing frameworks and avoid compliance pitfallsPractical security strategies you can implement todayNeed a partner to help you get on the right path with everything we talked about this season? Visit Trava Security to explore how our integrated services can transform security from a cost center into a competitive advantage: https://travasecurity.com/travas-servicesEpisode highlights:(00:00) Key lessons of Season 5(01:22) Debunking common compliance myths(03:19) How to future-proof your security strategy(06:51) Cybersecurity tips you can apply todayConnect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurity
  • Making Continuous Security Work: Inside the CTEM Framework 13.01.2026 10min
    For SMEs and startups, things are always changing—new projects, growing teams, and evolving products. Amidst this growth, cybersecurity often takes a backseat. However, protecting your business from cyber threats is more important than ever.In this episode, Anh Pham, Director of Penetration Testing and Security at Trava, explains how a robust Continuous Threat Exposure Management (CTEM) framework can help businesses stay secure. He also discusses how Penetration Testing as a Service (PTaaS) and Vulnerability Management as a Service (VMaaS) offer ongoing protection and risk management without the need for a full-time security team.Anh shares how partnering with cybersecurity experts can give you peace of mind, letting you focus on your business while staying ahead of potential threats. Tune in for practical advice on implementing CTEM, PTaaS, and VMaaS to ensure your business is safe and secure.Key takeaways:The role of PTaaS and VMaaS in continuous protectionThe benefits of partnering with cybersecurity expertsPractical steps to implement CTEM, PTaaS, and VMaaSWant to know exactly what to look for in a PTaaS provider? We’ve outlined everything you need to know in this guide: https://travasecurity.com/understanding-ptaasEpisode highlights:(00:00) The aspects of a robust CTEM strategy(01:15) Penetration Testing as a Service (PTaaS)(02:29) Vulnerability Management as a Service (VMaaS)(03:42) Why you need PTaaS and VMaaS in your CTEM framework(06:32) How to start small with CTEM(07:48) Making continuous cybersecurity affordable for SMEs and startupsConnect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with the guest:Anh Pham’s LinkedIn - https://www.linkedin.com/in/anhpham11/Connect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurity
  • Boost Your Cybersecurity with Continuous Threat Exposure Management (CTEM) 30.12.2025 11min
    Your business is constantly evolving. But how do you know where the weak spots are or which ones actually matter? In a fast-moving environment, understanding your vulnerabilities before attackers do is critical.In this episode, Anh Pham, Director of Penetration Testing and Security at Trava, breaks down why more businesses are moving toward Continuous Threat Exposure Management (CTEM). Anh explains the five key components of CTEM, how to tell if your business is ready to implement it, and what’s pushing organizations to take a more active, ongoing approach to cybersecurity.Key takeaways:Why CTEM outperforms traditional point-in-time testingThe five components of CTEM and how they work togetherHow evolving threats and expanding attack surfaces demand continuous validationReady to dive deeper into the continuous process? Get more info on CTEM and why it's important here: https://travasecurity.com/ctem-explainedEpisode highlights:(00:00) CTEM explained simply(02:38) How CTEM differs from point-in-time testing(04:29) The five components of a CTEM approach(09:25) When to adopt CTEMConnect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with the guest:Anh Pham’s LinkedIn - https://www.linkedin.com/in/anhpham11/Connect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurity
  • This is Your Cybersecurity Action Plan to Keep Your Business Safe in 2026 16.12.2025 9min
    As the new year approaches, now’s the time to refresh your cybersecurity strategy and kick old habits to the curb.In this special episode, Jara Rowe asks Trava experts one simple question: What should businesses focus on in 2026? Tune in for actionable advice that can immediately strengthen your business's security. From implementing essential tools to adopting best practices, these tips can make a real difference in how you prepare for the year ahead.Key takeaways:Why documenting changes and issues sets you up for smoother audits How smaller companies can reduce risk through MFA, pen testing, and AI policiesWhy treating security and compliance as one connected system prepares your business for the future Your business faces new challenges each day, and we want to set you up for success in 2026. Visit Trava Security to explore how our integrated services can transform security from a cost center into a competitive advantage: https://travasecurity.com/travas-servicesEpisode highlights:(00:00) Insights from cybersecurity experts(00:58) Why documentation saves you time during audits(01:28) How to stop attackers from impersonating your domain(01:51) The importance of regular testing(02:37) Centralizing controls, risks, and evidence(03:50) The easiest way to prevent data breaches(05:35) The mindset shift needed around security & compliance(06:41) Data visibility and protectionConnect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with the guests:Marie Joseph’s LinkedIn - https://www.linkedin.com/in/marie-joseph-a81394143/ Michael Magyar’s LinkedIn - https://www.linkedin.com/in/michael-magyar-cyqual/ Anh Pham’s LinkedIn - https://www.linkedin.com/in/anhpham11/ Dylan Goldberg’s LinkedIn - https://www.linkedin.com/in/dylanjgoldberg/ Jim Goldman’s LinkedIn - https://www.linkedin.com/in/jigoldman/ Dan Katt’s LinkedIn - https://www.linkedin.com/in/dkatt/ Kaitlin Zanoni’s LinkedIn - https://www.linkedin.com/in/kaitlin-zanoni/ Connect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurity
  • Keeping Up with Compliance: The Work That Comes After Certification 02.12.2025 11min
    Many small and mid-size businesses breathe a sigh of relief once they earn a compliance certification, but the work doesn’t stop there. Certifications like SOC 2, ISO, or CMMC aren’t one-time milestones. They’re ongoing commitments that require fresh evidence, updated controls, and regular monitoring.In this episode, Marie Joseph, Manager of Compliance Advisory at Trava, breaks down the reality of maintaining compliance over time. She discusses why frameworks evolve and how managed compliance services can take the stress off your team’s plate. Plus, she shares common mistakes businesses make during recertification and how to stay audit ready all year long.Key takeaways:How compliance frameworks evolve and why it mattersCommon mistakes companies make before audits and how to avoid themHow managed compliance services free up your team’s time One of the top tips Marie shared in this episode for staying proactive and organized with compliance is using a Compliance Calendar. You can download a free copy today—based on the same calendar Marie uses every day to manage SOC 2, ISO 27001, CMMC, NIST, and other frameworks: https://travasecurity.com/pod-compliance-calendarEpisode highlights:(00:00) Compliance:  What happens after you get certified?(02:32) Framework changes and renewals(05:17) Why compliance is never “done”(09:14) The audit mistake SMBs make most oftenConnect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with the guest:Marie Joseph’s LinkedIn - https://www.linkedin.com/in/marie-joseph-a81394143/ Connect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurity
  • You Bought a Compliance Automation Tool... Now What? 18.11.2025 13min
    Your compliance tools and automation say you're in the clear. Everything’s marked complete, deadlines are met, and the compliance dashboard is all green.But when it’s time for the audit, you’re still unprepared.In this episode, Kaitlin Zanoni, Security Advisor at Trava Security, breaks down the reality of compliance automation. She explains where these tools add real value, where they fall short, and why pairing automation with expert guidance is the only way to build an audit-ready compliance program.Key takeaways:Why compliance automation tools help with evidence collection but can’t replace expert guidanceHow overreliance on automation creates a false sense of security during auditsThe role of people, processes, and technology in building a sustainable compliance programWant to dive deeper into choosing the right compliance tool and how it fits into your audit journey? Check out our blog, Why the Right GRC Tool Is Critical for Compliance Certification, for actionable tips and expert insights: https://travasecurity.com/right-grc-toolEpisode highlights:(00:00) Tools and automation: Is this enough for compliance?(04:38) Common compliance automation tools(05:51) Limitations of automation tools(07:33) The importance of human experts(10:22) Choosing the Right GRC ToolConnect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with the guest:Kaitlin’s LinkedIn - https://www.linkedin.com/in/kaitlin-zanoni/ Connect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurity
  • SOC 2 Without the Stress: What Startups Should Do to Prepare 04.11.2025 10min
    If your business handles customer data, SOC 2 is not optional.It may not be on your radar today, but it will be soon. And when that time comes, how early you started will make all the difference.In this episode, Marie Joseph, Manager of Compliance Advisory at Trava, explains what it takes to prepare for SOC 2 certification. She shares what early prep should look like, how to make the audit less stressful, and why every company’s compliance checklist is unique.Whether you're just starting or already deep in the process, this conversation will help you avoid the most common mistakes and take SOC 2 seriously before you’re forced to.Want to make your SOC 2 prep more efficient without slowing down your team? Check out our blog, How To Get SOC 2 Certified Without Slowing Down Your Engineering Team, for practical tips on preparing smart, staying organized, and keeping your business moving while you get audit-ready: https://travasecurity.com/soc-2-without-slowing-downKey takeaways:What most startups get wrong about SOC 2 prepWhy starting early sets you up for a smoother SOC 2 journeyHow GRC tools and consultants help you prepare for auditsEpisode highlights:(00:00) SOC 2 preparation: More than just a checklist(02:37) How GRC tools help in SOC 2 prep(03:35) When to bring in consultants or advisors(04:37) The role of an internal champion for SOC 2(06:51) Preparation for Type 1 vs. Type 2(07:46) The biggest mistakes startups makeConnect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with the guest:Marie Joseph’s LinkedIn - https://www.linkedin.com/in/marie-joseph-a81394143/ Connect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurity
  • SOC 2 Certification in 60 Days? Here’s What They’re Not Telling You 20.10.2025 14min
    Some companies boast about earning their SOC 2 certification in just two months. While technically possible, that speed usually comes with stress, shortcuts, and costly tradeoffs.In this episode, Marie Joseph, Manager of Compliance Advisory at Trava, explains why true SOC 2 compliance takes more than 60 days. She breaks down the difference between Type 1 and Type 2 reports, outlines what a realistic timeline looks like, and highlights the team effort required to build a sustainable program.Whether you're starting from zero or in the process of certification, this is your SOC 2 reality check.Want to know what it really takes to get SOC 2 certified? Check out our blog, How To Prove SOC 2 Compliance, to see what goes into building a strong program and preparing for a successful audit: https://travasecurity.com/proving-SOC2Key takeaways:The difference between SOC 2 Type 1 and Type 2 What a realistic SOC 2 timeline looks likeHow team bandwidth, funding, and tools affect SOC 2 certificationEpisode highlights:(00:00) SOC 2 in two months: Myth or reality?(03:26) The SOC 2 certification process(06:29) Understanding SOC 2 Type 1 vs. Type 2(10:37) Factors affecting SOC 2 certification speed(11:58) Do you need SOC 2 for VC funding?Connect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with the guest:Marie Joseph’s LinkedIn - https://www.linkedin.com/in/marie-joseph-a81394143/ Connect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurity
  • Introducing Season 5 of The Tea on Cybersecurity 07.10.2025 3min
    Cybersecurity can feel overwhelming with its many acronyms, shifting rules, and conflicting advice.That’s why Season 5 of The Tea on Cybersecurity is all about separating fact from fiction. Host Jara Rowe kicks things off by identifying the common questions business leaders have about SOC 2 certification, automation tools, and AI policies. This season keeps episodes short and to the point, so you can get the info you need without wasting time.Subscribe, share, and send in your questions. Season 5 is just getting started.Curious about what compliance really takes and what’s myth versus reality? Start with our blog, How To Prove SOC 2 Compliance, to get a clear picture of what it takes to get audit-ready: https://travasecurity.com/proving-SOC2Episode highlights:(00:00) Welcome to Season 5 of The Tea on Cybersecurity(01:50) Common questions on SOC 2, automation, and AI(02:57) What’s new this seasonConnect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurity
  • Key Lessons from Season 4 of The Tea on Cybersecurity 12.08.2025 6min
    If there’s one key takeaway from Season 4 of The Tea on Cybersecurity, it’s that cybersecurity is a shared responsibility. With this in mind, host Jara Rowe wraps up the season by sharing valuable insights that everyone can use. She reflects on the most impactful lessons about compliance, AI, and penetration testing. Key takeaways:The importance of vCISOs and cyber engineersHow to approach penetration testing and PTaaSWhy transparency and training are essential for AI safetyYour business faces new challenges, from sophisticated AI threats to strict CMMC requirements. Don't let compliance slow your growth. Visit Trava Security to explore how our integrated services—including vCISO leadership, compliance management, and proactive risk assessments—can transform security from a cost center into a competitive advantage: https://travasecurity.com/travas-services Episode highlights:(00:00) Today’s topic: Key insights from this season (01:16) The role of vCISOs and cyber engineers(02:47) Responsible AI use(03:51) Penetration testing and PTaaS for small teamsConnect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurity
  • Breaking Down PTaaS: Continuous Security for Modern Companies 29.07.2025 19min
    Most companies continually push code, launch new features, and update their infrastructure. However, for many businesses, security testing occurs only once a year. That gap leaves systems exposed to risks that go unnoticed.In this episode, Anh Pham, Director of Penetration Testing at Trava, explains the concept of Penetration Testing as a Service (PTaaS). He shares how it works and why it's more beneficial than one-time pentests. You’ll also learn how AI fits into the picture and what to consider when choosing a provider.Key takeaways:The difference between PTaaS and traditional pentestingHow PTaaS supports fast-changing environmentsThe qualities of a trustworthy PTaaS provider PTaaS is just one part of a bigger security picture. Learn how Continuous Threat Exposure Management (CTEM) helps you stay ahead of risks in our blog: What Is CTEM and Why It Matters for Modern Security Programs: https://travasecurity.com/ctem-explained Episode highlights:(00:00) Today’s topic: Penetration Testing as a Service(03:16) PTaaS vs one-time pentests(08:36) How PTaaS works(11:59) Choosing a secure PTaaS provider(13:17) Can AI help in PTaaS?(15:22) A key reminder for businesses getting startedConnect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with the guest:Anh Pham’s LinkedIn - @anhpham11Connect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurityListen to past episodes:Unveiling Vulnerabilities: The Power of Pen Testing - https://travasecurity.com/learn-with-trava/podcasts/unveiling-vulnerabilities-the-power-of-pen-testing-in-cybersecurity/Proving Compliance and Security Effectiveness Through Pen Testing - https://travasecurity.com/learn-with-trava/podcasts/proving-compliance-and-security-effectiveness-through-pen-testing/
  • Understanding Cyber Engineering to Build Stronger Security 15.07.2025 23min
    Cyber engineering is a broad and often misunderstood field, covering everything from cloud architecture to compliance. But one thing is clear: someone needs to take responsibility for the security of your business’s digital infrastructure.In this episode, host Jara Rowe is joined by Michael Magyar, vCISO at Trava Security, to explore the intersection of cybersecurity, compliance, and engineering. Michael shares what smart architecture looks like in practice, where organizations often fall short, and how emerging trends like AI impact cyber engineering.Key takeaways:How smart cyber engineering impacts security and operationsThe influence of AI on cyber engineering tasksWhen to seek outside help for technical implementationIf you’re curious about the top risks companies face in cloud and SaaS environments—and how to address them—check out our blog: Seven Security Issues in SaaS and Cloud Computing: https://travasecurity.com/saas-security-issues Episode highlights:(00:00) Today’s topic: Cyber engineering(05:29) The push for more security and compliance(07:44) Being intentional with security architecture(10:33) Cybersecurity engineering in the real world(13:52) Cyber engineering trends and AI (19:37) Discerning when to hire outside expertsConnect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with the guest:Michael Magyar’s LinkedIn - @michael-magyar-cyqualConnect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurity
  • The Core Pillars of AI Governance 01.07.2025 32min
    The rapid adoption of AI brings opportunities, yet new risks. Strong governance enables organizations to remain innovative while maintaining trust and protecting data.In this episode, host Jara Rowe welcomes Jim Goldman, Co-Founder of Trava Security, to discuss how clear oversight, board engagement, and high-quality data enable the creation of ethical AI that aligns with business goals.They outline practical steps, common blind spots, and proven frameworks for trustworthy automation.Key takeaways:AI governance versus compliance in plain languageWhy data quality shapes reliable machine outputHow leaders and teams share accountability from policy to practiceContinue your learning with our blog post, "How SaaS Companies Can Navigate AI Compliance Challenges," for best practices and framework details: https://travasecurity.com/navigating-ai-compliance Episode highlights:(00:00) Today’s topic: AI Governance(02:46) Governance reaches the boardroom(04:09) Big shifts in NIST CSF 2.0(06:01) Governance versus compliance explained(07:45) Data quality risks in AI(10:55) Core parts of a governance framework(13:32) Roles and ownership across teams(14:55) Designing ethical, transparent AI(19:06) Proving accountability in decisions(23:37) Easing public worries with openness(26:41) Criminal abuse and law responseConnect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with the guest:Jim Goldman’s LinkedIn - @jigoldmanConnect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurity
  • Don’t Overtrust the Robots: The Real Tea on AI Compliance 17.06.2025 22min
    Businesses rely on AI for everything from streamlining communication to managing hiring and forecasting trends. It’s fast, efficient, and deeply embedded in daily operations. But as AI becomes more common, one critical piece is often overlooked: compliance.In this episode, Jara Rowe sits down with Dr. Marwan Omar, Chief AI Officer at Insight Assurance, to talk about the growing need for AI compliance. They explore what it really means, why it’s not just a concern for tech giants, and how overlooking it could expose your business to legal, ethical, and reputational risks.Key takeaways:What makes AI compliance different from traditional IT complianceWhere to start with AI risk assessmentsHow real companies have gotten AI compliance wrongYou heard Marwan discuss the critical need to address AI bias, transparency, and regulation (like the EU AI Act). Don't just audit—mitigate the risk! Explore Trava's AI Risk Management Services to ensure your systems are ethical, secure, and compliant with key frameworks like NIST AI RMF and ISO 42001: https://travasecurity.com/ai-risk-services Episode highlights:(00:00) Today’s topic: AI compliance and why it matters (05:23) Key laws shaping AI compliance today(07:25) The nuances of AI compliance(10:14) First steps to build AI compliance internally(13:26) How explainability strengthens trust in AI models(15:32) Challenges with regulations and data privacy(18:24) Staying informed as AI laws evolveConnect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with the guest:Marwan Omar’s LinkedIn - @dr-marwan-omarConnect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurity
  • Proving Compliance and Security Effectiveness Through Pen Testing 03.06.2025 26min
    Many companies start penetration testing to address compliance requirements. However, it can also provide valuable insights beyond just meeting standards.In this episode, host Jara Rowe sits down with Anh Pham and Christina Annechino from Trava to talk about how pen tests uncover hidden risks and strengthen your cybersecurity. They explain compliance frameworks, typical pen test schedules, and common mistakes to avoid.Key takeaways:Compliance frameworks and their pen test requirementsThe different types of penetration testingHow to prepare your environment for a successful pen testThe podcast broke down Pen Tests and Vulnerability Scans. Now, read "What Are the Different Types of Cybersecurity Assessments?" to understand where each security check fits in your overall risk program: https://travasecurity.com/cyber-assessments Episode highlights:(00:00) Today’s topic: Penetration Testing and Compliance(03:42) Pen testing compliance frameworks(05:46) The difference between vulnerability scans and pen tests(09:11) How often to conduct pen tests(11:04) Qualities of a good penetration testing vendor (14:34) Making pen testing work on a budget(16:49) Scoping mistakes that limit test outcomes(18:53) Using pen tests to improve overall cybersecurityConnect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with the guest:Anh Pham’s LinkedIn - @anhpham11Christina Annechino’s LinkedIn - @christinaannechinoConnect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurityListen to a related episode:Unveiling Vulnerabilities: The Power of Pen Testing - https://travasecurity.com/learn-with-trava/podcasts/unveiling-vulnerabilities-the-power-of-pen-testing-in-cybersecurity/
  • Getting CMMC Right: Scope, Budget, and Certification Tips 20.05.2025 26min
    Think compliance is just an IT problem? It’s a revenue problem, too. Without it, some contracts will stay out of reach.In this episode, Jara Rowe talks with Tom Greco, vCISO at Trava Security, about what companies need to know about the Cybersecurity Maturity Model Certification (CMMC). It’s a Department of Defense requirement that verifies whether companies are securely handling Controlled Unclassified Information (CUI). Tom Greco explains what CMMC involves, how scoping affects your readiness, and how to maintain compliance over time. In short, if you want to win or keep federal contracts, CMMC compliance isn’t optional.Key takeaways:What CMMC is and why it existsThe importance of accurate scopingTools and tips to maintain CMMC complianceYou don't have to be. We covered the essentials, but to get a clear, concise breakdown of the entire framework, read our easy-to-understand guide: "What Is CMMC in a Nutshell?" Click to gain clarity on the CMMC levels and start securing your DoD contracts today: https://travasecurity.com/cmmc-nutshell Episode highlights:(00:00) Today’s topic: What is CMMC?(02:20) What CMMC means for your business(06:05) The nuances of scoping(10:07) How contracts set your CMMC level (13:44) Self-assessment vs third-party audits(17:36) Maintaining CMMC compliance over time(22:17) Perform gap assessments ASAP Connect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with the guest:Thomas Greco’s LinkedIn - @thomas-grecoConnect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurity
  • Security Leadership Without the Full-Time Price Tag for Small Teams 06.05.2025 27min
    Is your business one cyberattack away from chaos? Most companies don’t think about cybersecurity until they’re in crisis mode—but by then, the damage is done.In this episode, Jara Rowe talks with Michael Magyar, an experienced virtual Chief Information Security Officer (vCISO). They cover what a vCISO does, why more companies are choosing virtual over full-time, and how to know when it’s time to bring one in. Michael shares examples of helping businesses avoid costly mistakes, explains how vCISOs assess risk, and offers advice for small teams trying to do more with less.Key takeaways:Common cybersecurity challenges vCISOs help solveWhat a typical engagement with a vCISO looks likeAdvice for SMBs with limited budgets trying to prioritize cybersecurityYou know what a vCISO is and the value they bring. The next step is finding the perfect fit for your business. Download Trava's comprehensive guide, "Steps to Selecting Your vCISO Partner," for expert insights, actionable tips, and a clear roadmap for choosing the right executive-level security expertise: https://travasecurity.com/selecting-vciso Episode highlights:(00:00) Today’s topic: Breaking down the role of a vCISO(05:32) vCISO vs. traditional in-house CISO(07:11) Why small businesses benefit from a vCISO(09:53) Real examples of vCISOs making a difference(13:52) What it’s like working with a vCISO(16:00) Key indicators your business needs a vCISO(20:54) How to prioritize cybersecurity on a budgetConnect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with the guest:Michael Magyar’s LinkedIn - @michael-magyar-cyqualConnect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurity
  • Cybersecurity Lingo Explained: vCISO, PII, and More 21.04.2025 23min
    Cybersecurity lingo can be overwhelming, but once you get the hang of the essentials, staying secure becomes much easier.In this episode, host Jara Rowe sits down with Marie Joseph, Senior Security Advisor at Trava, to break down key terms like vCISO, PII, and cybersecurity maturity models. They also differentiate between terms like hacker vs. threat actor and firewall vs. antivirus by highlighting the nuances that matter most. Plus, Marie reveals why continuous compliance is crucial, and how concepts like attack surface and risk tolerance fit into the bigger picture of your security strategy.Key takeaways:Essential cybersecurity terms and definitions: vCISO, PII, and more  The importance of understanding and managing your attack surfaceWhy cybersecurity compliance can’t be a one-time effortWant to learn more jargon? Download the essential resource to understand the language of compliance: Conquer Compliance Jargon: Download the Free Cybersecurity Compliance Glossary: https://travasecurity.com/conquer-jargon Episode highlights:(00:00) Today’s topic: Understanding cybersecurity terms(01:47) What is a vCISO, and why it benefits small businesses(02:54) Definition of PII, BCP, SIEM, DevSecOps, and BCRA (08:40) Hackers vs. threat actors Explained(10:28) Why businesses need an antivirus and a firewall(13:37) Patch management and cybersecurity attack surfaces(16:04) Continuous cybersecurity compliance(21:27) Recapping cybersecurity essentialsConnect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with the guest:Marie Joseph’s LinkedIn - @marie-joseph-a81394143Connect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blogLinkedIn - @travasecurityYouTube - @travasecurity
  • Introducing Season 4 of The Tea on Cybersecurity 07.04.2025 11min
    Cyber threats are evolving, security rules are tightening, and the idea of a ‘safe network’ is quickly disappearing. So what does that mean for businesses and individuals trying to stay protected?To kick off Season 4, host Jara Rowe revisits key lessons from past seasons and unpacks the biggest cybersecurity trends shaping the industry today. This season will take a deeper look at AI governance, compliance challenges, and penetration testing—critical areas companies can’t afford to ignore.With cybersecurity changing fast, businesses must decide how to adapt before they fall behind. The answers start here.Key takeaways:Why cybersecurity is a team effort, not just IT’s jobHow AI is changing both cyber defense and cybercrimeHow vCISOs are filling critical security gaps for businessesEpisode highlights:(00:00) Today’s topic: How cybersecurity is evolving (01:21) Major lessons from past seasons(05:38) Current cybersecurity trends(08:26) What to expect in season 4Connect with the host:Jara Rowe’s LinkedIn - @jararoweConnect with Trava:Website - www.travasecurity.comBlog - www.travasecurity.com/learn-with-trava/blog/LinkedIn - @travasecurityYouTube - @travasecurity
  • Recap on Season 3 - Receipts on The Tea on Cybersecurity 02.07.2024 22min
    We’ve come to the end of another Season of The Tea on Cybersecurity and you know what that means. Join host Jara Rowe in her ultimate receipts from season 3. She highlights the most important things she has learned from her guests this season including why MFA is key to keeping yourself safe online, how to manage vulnerabilities, what steps you need in preparing for cybersecurity incidents, and how to cultivate trust and transparency within your organizations.Listen in as Jara revisits her conversations with all of our Season 3 guests including Trava CEO Jim Goldman, Craig Saldanha and Mario Vlieg with Insight Insurance, and John Boomershine with BlankInkIT, among others. In this episode, you’ll learn:Multi-Factor Authentication (MFA) is Your Best Friend: It's like adding an extra lock to your door to keep the bad guys out—and who doesn’t want that extra peace of mind? Enabling MFA can be a game-changer in protecting against cyber vulnerabilities. It's easy to implement and adds that essential layer of security without the hassle!Bring Your Own Device (BYOD) Take Control of Your Digital Inventory: This is a deep dive on how to make sure all devices, company-owned or personal, are secure and compliant in this digitally diverse world. This is super relevant for those offering flexible work arrangements and want to stay ahead in your cybersecurity game.Establishing Trust and Transparency is Key: This isn’t just about securing your systems but also about earning and maintaining the trust of your customers and stakeholders— whether it’s securing communications through encryption or ensuring third-party vendors are just as vigilant. Visit the Trava website to find actionable guides, compliance solutions, and the tools you need to master MFA, asset control, and continuous vulnerability management: https://travasecurity.com/learn Jump into the conversation:[00:00 - 00:41] Introduction to the Tea on Cybersecurity podcast[00:41 - 3:46] The importance of MFA[03:47 - 05:07] MFA in cyber hygiene[05:08 - 06:02] Employee training as a vital part of cybersecurity defense strategy[06:52 - 07:45] BOYD (bring your own device) and the challenges of inventory management[07:45 - 10:07] A different way to think about risk[10:08 - 12:12] The difference between risks and vulnerabilities[12:18 - 13:24] The difference between breaches and incidents[13:25 - 14:15] What to do if an incident should occur[14:19 - 16:17] Steps to take if an incident were to occur with a third-party vendor[16:18 - 17:58] Why trust is foundational to cybersecurity[17:59 - 19:03] How a compliance framework is like a cookbook[19:03 - 21:21] Cybersecurity in healthcare and bankingConnect with the host:Jara Rowe’s LinkedInConnect with Trava:Website www.travasecurity.comBlog www.travasecurity.com/blogLinkedIn @travasecurityYouTube @travasecurity

Popular di

Podcast ini turut muncul dalam senarai podcast negara-negara ini.