CISO Tradecraft®

By G Mark Hardy & Ross Young

Listen to a podcast, please open Podcast Republic app. Available on Google Play Store and Apple App Store.


Category: Technology

Open in Apple Podcasts


Open RSS feed


Open Website


Rate for this podcast

Subscribers: 41
Reviews: 0
Episodes: 282

Description

You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level.

© Copyright 2025, National Security Corporation. All Rights Reserved


Episode Date
#282 - Top 10 Agentic AI Attacks (with Rock Lambros)
May 04, 2026
#281 - SIEM Secrets They Don’t Tell You (with Anton Chuvakin & Alex Hurtado)
Apr 27, 2026
#280 - Mythos and the Future of Vulnerability Operations (with Gadi Evron)
Apr 20, 2026
#279 - AI Readiness (with JP Bourget)
Apr 13, 2026
#278 - RSAC Takeaways: AI SOC, Agent Security, and What Cyber Marketing Gets Wrong
Apr 07, 2026
#277 - From SaaS to AI Agents: Gone in 60 Seconds
Mar 30, 2026
#276 - How is AI Reshaping Fraud (with Brian Long)
Mar 23, 2026
#275 - How to Secure Vibe Code (with Shahar Man)
Mar 16, 2026
#274 - The State of Stress in Cyber (with Steve Shelton)
Mar 09, 2026
#273 - Creating a Wisdom-Led SOC (with Oren Saban)
Mar 02, 2026
#272 - Data Centric Platform Play (with EJ Pappas)
Feb 23, 2026
#271 - A Life of Service (with Chris Inglis)
Feb 16, 2026
#270 - And What is Truth?
Feb 03, 2026
#269 - Changing Third Party Risk Management (with Nate Lee)
Jan 26, 2026
#268 - Zero Trust isn't a product (with George Finney)
Jan 19, 2026
#267 - Busy is the New Stupid (with Ross Young)
Jan 12, 2026
#266 - Why CISOs Miss The Next Big Security Challenge (with Richard Stiennon)
Jan 05, 2026
#265 - 12 CISO Templates (with Ross Young)
Dec 29, 2025
#264 - Behavioral Insights (with Dr. Dustin Sachs)
Dec 22, 2025
#263 - Stopping Attacks To Your Cloud Office Environment (with Rajan Kapoor)
Dec 15, 2025
#262 - AI Mastery for CISOs: What You Must Know
Dec 08, 2025
#261 - Vibe Coding Security (with Neatsun Ziv)
Dec 01, 2025
#260 - Mastering Defense Against Configurations ( with Yuriy Tsibere)
Nov 24, 2025
#259 - Transforming Security Operations (with Brian Carbaugh and William Macmillan)
Nov 17, 2025
#258 - From Invention to Entrepreneurship (with Jeri Ellsworth)
Nov 10, 2025
#257 - Patch or Perish (with Ross Young)
Nov 03, 2025
#256 - Maximize Your Cybersecurity Budgets (with Ross Young)
Oct 27, 2025
#255 - Maximize the Outcomes Per Dollar in Cyber (with Ross Young)
Oct 20, 2025
#254 - AI, Privacy, & Security Insights (with Aimee Cardwell)
Oct 13, 2025
#253 - DARPA’s AI Cyber Challenge Unveiled (with Andrew Carney)
Oct 06, 2025
#252 - Master Storytelling for CISOs (with Neal Foard)
Sep 29, 2025
#251 - AI Just Changed Data Security Requirements (with Ronan Murphy)
Sep 22, 2025
#250 - Understanding Vulnerabilities, Exploits, and Cybersecurity
Sep 15, 2025
#249 - Unveiling AI and Crypto Threats with Microsoft's Tomas Roccia
Sep 08, 2025
#248 - A Black Hat Chat with ThreatLocker CEO Danny Jenkins
Sep 01, 2025
#247 - What most leaders don't understand about AI (with Dave Lewis)
Aug 25, 2025
#246 - Tim Brown on SolarWinds: What Every CISO Should Know
Aug 18, 2025
#245 - Mastering Cybersecurity Recruitment and Career Growth (with Casey Marquette)
Aug 11, 2025
#244 - Breaking into Cybersecurity (with Christophe Foulon)
Aug 04, 2025
#243 - Navigating Hacker Summer Camp in 2025
Jul 29, 2025
#242 - The Secret to Career Success: Your Personal Board of Directors
Jul 21, 2025
#241 - The OWASP Threat and Safeguard Matrix (with Ross Young)
Jul 14, 2025
#240 - From CruiseCon to AI Threats (with Ira Winkler)
Jul 07, 2025
#239 - Actionable Gamification and Lasting Success (with Yu-Kai Chou)
Jun 30, 2025
#238 - The Impact of the Israel Iran Conflict (with Nathan Case)
Jun 23, 2025
#237 - Build a World Class SOC (with Carson Zimmerman)
Jun 16, 2025
#236 - Build a World Class GRC Program (with Matt Hillary)
Jun 09, 2025
#235 - Grey is the New Black (with Ryan Gooler)
Jun 02, 2025
#234 - Model Context Protocol (MCP)
May 26, 2025
#233 - Web 3.0 Explained (with Aaron Markell)
May 19, 2025
#232 - Inside The 2025 Verizon Data Breach Investigations Report
May 12, 2025
#231 - Tackle Your Technical Debt
May 05, 2025
#230 - How To Make Your AI Less Chatty (with Sounil Yu)
Apr 28, 2025
#229 - Understanding the Critical Role of CVEs and CVSS
Apr 21, 2025
#228 - CIS CSAT (with Scott Gicking)
Apr 14, 2025
#227 - The 30 Year CISO Evolution
Apr 07, 2025
#226 - Vulnerability Management (with Chris Hughes)
Mar 31, 2025
#225 - The Full Irish
Mar 24, 2025
#224 - The Evolution of Data Loss Prevention (DLP)
Mar 17, 2025
#223 - A CISO Primer on Agentic AI
Mar 10, 2025
#222 - 40 Years of Career Advice in 40 Minutes
Mar 03, 2025
#221 - Microsoft Majorana is Taking the Quantum Leap
Feb 24, 2025
#220 - Executive Updates to AI
Feb 17, 2025
#219 - The Professionalization of CISOs (with Steve Zalewski & Tyson Kopczynski)
Feb 10, 2025
#218 - How AI Changes Talent Management (with Colleen Lennox)
Feb 03, 2025
#217 - Includes No Dirt (with Bill Dougherty)
Jan 27, 2025
#216 - The TTPs of a Security Champions Program (with Dustin Lehr)
Jan 20, 2025
#215 - CISO Predictions for 2025
Jan 13, 2025
#214 - Deceive to Detect (with Yuriy Gatupov)
Jan 06, 2025
#213 - How to Build a Successful Cybersecurity Startup (with Ross Haleliuk)
Dec 30, 2024
#212 - Repeatable, Attestable, and Defensible AI (with AWS's Former Deputy CISO Merritt Baer)
Dec 23, 2024
#211 - Allowlisting and Ringfencing (with Kieran Human)
Dec 16, 2024
#210 - Salt Typhoon and Vulnerable Telecoms
Dec 09, 2024
#209 - AI Singularity (with Richard Thieme)
Dec 02, 2024
#208 - Insider Threat (with Shawnee Delaney)
Nov 25, 2024
#207 - CISO Burnout (with Raghav Singh)
Nov 18, 2024
#206 - Ira Winkler CruiseCon Founder
Nov 11, 2024
#205 - Wisdom from the 1st Cyber Colonel (JC Vega)
Nov 04, 2024
#204 - Shadows and Zombies in the Data Center
Oct 28, 2024
#203 - Be SOCcessful with the SOC-CMM
Oct 21, 2024
#202 - Cybersecurity Crisis: Are We Failing the Next Generation?
Oct 14, 2024
#201 - Avoiding Hurricanes in the Cloud
Oct 07, 2024
#200 - Copywriting AI (with Mark Rasch)
Sep 30, 2024
#199 - How to Secure Generative AI
Sep 23, 2024
#198 - Securing the Business Processes
Sep 16, 2024
#197 - Fedshark's Blueprint for Cost Effective Risk Reduction
Sep 09, 2024
#196 - Cyber Thrills and Author Quills (with Deb Radcliff)
Sep 02, 2024
#195 - Pentesting for Readiness not Compliance (with Snehal Antani)
Aug 26, 2024
#194 - The IAM Masterclass
Aug 19, 2024
#193 - Security Team Operating System (with Christian Hyatt)
Aug 12, 2024
#192 - From Cyber Burnout to VCISO Bliss (with Olivia Rose)
Aug 05, 2024
#191 - From Breach to Bench (with Thomas Ritter)
Jul 29, 2024
#190 - Lawyers, Breaches, and CISOs: Oh My (with Thomas Ritter)
Jul 22, 2024
#189 - Emotional Intelligence
Jul 15, 2024
#188 - Securing Small Businesses
Jul 08, 2024
#187 - Ensuring Profitable Growth
Jun 24, 2024
#186 - AI Coaching (with Tom Bendien)
Jun 17, 2024
#185 - Ethics and Artificial Intelligence (AI)
Jun 10, 2024
#184 - Complexity is Killing Us
Jun 03, 2024
#183 - Navigating the Cloud Security Landscape (with Chris Rothe)
May 27, 2024
#182 - Shaping the SOC of Tomorrow (with Debbie Gordon)
May 20, 2024
#181 - Inside the 2024 Verizon Data Breach Investigations Report
May 13, 2024
#180 - There's Room For Everybody In Your Router (with Giorgio Perticone)
May 06, 2024
#179 - The 7 Broken Pillars of Cybersecurity
Apr 29, 2024
#178 - Cyber Threat Intelligence (with Jeff Majka & Andrew Dutton)
Apr 22, 2024
#177 - 2024 CISO Mindmap (with Rafeeq Rehman)
Apr 15, 2024
#176 - Reality-Based Leadership (with Alex Dorr)
Apr 08, 2024
#175 - Navigating NYDFS Cyber Regulation
Apr 01, 2024
#174 - OWASP Top 10 Web Application Attacks
Mar 25, 2024
#173 - Mastering Vulnerability Management
Mar 18, 2024
#172 - Table Top Exercises
Mar 11, 2024
#171 - Navigating Software Supply Chain Security (with Cassie Crossley)
Mar 04, 2024
#170 - Responsibility, Accountability, and Authority
Feb 26, 2024
#169 - MFA Mishaps
Feb 19, 2024
#168 - Cybersecurity First Principles (with Rick Howard)
Feb 12, 2024
#167 - Cybersecurity Apprenticeships (with Craig Barber)
Feb 05, 2024
#166 - Cyber Acronyms You Should Know
Jan 29, 2024
#165 - Modernizing Our SOC Ingest (with JP Bourget)
Jan 22, 2024
#164 - The 7 Lies in Cyber
Jan 15, 2024
#163 - Operational Resilience
Jan 08, 2024
#162 - CISO Predictions for 2024
Jan 01, 2024
#161 - Secure Developer Training Programs (with Scott Russo) Part 2
Dec 25, 2023
#160 - Secure Developer Training Programs (with Scott Russo) Part 1
Dec 18, 2023
#159 - Refreshing Your Cybersecurity Strategy
Dec 11, 2023
#158 - Building a Data Security Lake (with Noam Brosh)
Dec 04, 2023
#157 - SOC Skills (with Hasan Eksi) Part 2
Nov 27, 2023
#156 - SMB CISO Challenges (with Kevin O’Connor)
Nov 20, 2023
#155 - SOC Skills (with Hasan Eksi) Part 1
Nov 13, 2023
#154 - Data Protection (with Amer Deeba)
Nov 06, 2023
#153 - Game-Based Learning (with Andy Serwin & Eric Basu)
Oct 30, 2023
#152 - Speak My Language (with Andrew Chrostowski)
Oct 23, 2023
#151 - Cyber War
Oct 16, 2023
#150 - Measuring Results
Oct 09, 2023
#149 - Board Perspectives
Oct 02, 2023
#148 - Threat Modeling (with Adam Shostack)
Sep 25, 2023
#147 - Betting on MFA
Sep 18, 2023
#146 - Living in a Materiality World
Sep 11, 2023
#145 - The Cost of Cyber Defense
Sep 04, 2023
#144 - Handling Regulatory Change
Aug 28, 2023
#143 - Authentication, Rainbow Tables, and Password Managers
Aug 21, 2023
#142 - Powerful Questions
Aug 14, 2023
#141 - Emerging Risks (with The Chertoff Group)
Aug 07, 2023
#140 - Bobby the Intern
Jul 31, 2023
#139 - Insider Threat Operations (with Jim Lawler)
Jul 24, 2023
#138 - Updating the Mindmap (with Rafeeq Rehman)
Jul 17, 2023
#137 - 1% Better Leadership (with Andy Ellis)
Jul 10, 2023
#136 - From Hacking to Hardcover (with Bill Pollock)
Jul 03, 2023
#135 - Board Decks (with Demetrios Lazarikos)
Jun 26, 2023
#134 - Ransomware Response (with Ricoh Danielson)
Jun 19, 2023
#133 - The Seesaw of Cyber Recruiting (with Lee Kushner)
Jun 12, 2023
#132 - Founding to Funding (with Cyndi and Ron Gula)
Jun 05, 2023
#131 - Framing Executive Discussions
May 29, 2023
#130 - Financial Planning (with Logan Jackson)
May 22, 2023
#129 - Protecting Your Family
May 15, 2023
#128 - How do CISOs spend their time?
May 08, 2023
#127 - How to Stop Bad Guys from Staying on Your Network (with Kevin Fiscus)
May 01, 2023
#126 - ChatGPT & Generative AI (with Konstantinos Sgantzos)
Apr 24, 2023
#125 - Cyber Ranges (with Debbie Gordon)
Apr 17, 2023
#124 - Simple, Easy, & Cheap Cybersecurity Measures (with Brent Deterding)
Apr 10, 2023
#123 - Accepted Cyber Strategy (with Branden Newman)
Apr 03, 2023
#122 - Methodologies for Analysis (with Christopher Crowley)
Mar 27, 2023
#121 - Legal Questions (with Evan Wolff)
Mar 20, 2023
#120 - Negotiating Your Best CISO Package (with Michael Piacente)
Mar 13, 2023
#119 - Ethics (with Stephen Northcutt)
Mar 06, 2023
#118 - Data Engineering (with Gal Shpantzer)
Feb 27, 2023
#117 - Good Governance (with Sameer Sait)
Feb 20, 2023
#116 - A European view of CISO responsibilities (with Michael Krausz)
Feb 13, 2023
#115 - The Business Case for a Global Lead of Field Cybersecurity (with Joye Purser)
Feb 06, 2023
#114 - One Vendor to Secure Them All
Jan 30, 2023
#113 - SAST Security (with John Steven)
Jan 23, 2023
#112 - Attack Surface Management (with Richard Ford)
Jan 17, 2023
#111 - Leading with Style
Jan 09, 2023
#110 - CISO Predictions for 2023
Jan 02, 2023
#109 - The Right Stuff
Dec 19, 2022
#108 - Show Me The Money (with Nick Vigier)
Dec 12, 2022
#107 - Consolidating Vulnerability Management (with Jeff Gouge)
Dec 05, 2022
#106 - How to Win Your First CISO Role
Nov 28, 2022
#105 - Start Me Up (with Bob Cousins)
Nov 21, 2022
#104 - Breach and Attack Simulation (with Dave Klein)
Nov 14, 2022
#103 - Listening to the Wise (with Bill Cheswick)
Nov 07, 2022
#102 - Mentorship, Sponsorship, and A Message to Garcia
Oct 31, 2022
#101 - SaaS Security Posture Management (with Ben Johnson)
Oct 24, 2022
#100 - 7 Ways CISOs Setup for Success
Oct 17, 2022
#99 - Cyberwar and the Law of Armed Conflict (with Larry Dietz)
Oct 10, 2022
#98 - Outrunning the Bear
Oct 03, 2022
#97 - Mobile Application Security (with Brian Reed)
Sep 26, 2022
#96 - The 9 Cs of Cyber
Sep 19, 2022
#95 - Got any Data Security (with Brian Vecci)
Sep 12, 2022
#94 - Easier, Better, Faster, & Cheaper Software
Sep 05, 2022
#93 - How to Become a Cyber Security Expert
Aug 29, 2022
#92 - Updating the Executive Leadership Team on Cyber
Aug 22, 2022
#91 - Hacker Summer Camp
Aug 15, 2022
#90 - A CISO’s Guide to Pentesting
Aug 08, 2022
#89 - Connecting the Dots (with Sean Heritage)
Aug 01, 2022
#88 - Tackling 3 Really Hard Problems in Cyber (with Andy Ellis)
Jul 25, 2022
#87 - From Hunt Team to Hunter (with Bryce Kunz)
Jul 18, 2022
#86 - The CISO MindMap (with Rafeeq Rehman)
Jul 11, 2022
#85 - The Fab 5 Security Outcomes Study (with Helen Patton)
Jul 04, 2022
#84 - Gaining Trust (with Robin Dreeke)
Jun 27, 2022
#83 - Cyber Defense Matrix Reloaded (with Sounil Yu)
Jun 20, 2022
#82 - Cyber Defense Matrix (with Sounil Yu)
Jun 13, 2022
#81- Career Lessons from a CISO (with John Hellickson)
Jun 06, 2022
#80 - Breaking Backbones (with Deb Radcliff)
May 30, 2022
#79 - Addressing the Top CEO Concerns
May 23, 2022
#78 - Business Objectives & 5 CISO Archetypes (with Christian Hyatt)
May 16, 2022
#77 - Countering Corporate Espionage
May 09, 2022
#76 - The Demise of the Cybersecurity Workforce
May 02, 2022
#75 - Avoiding Death By PowerPoint
Apr 25, 2022
#74 - Pass the Passwords
Apr 18, 2022
#73 - Wonderful Winn Schwartau
Apr 11, 2022
#72 - Logging In with SIEMs (with Anton Chuvakin)
Apr 04, 2022
#71 - Lessons Learned as a CISO (with Gary Hayslip)
Mar 28, 2022
#70 - Partnership is Key
Mar 21, 2022
#69 - Aligning Security Initiatives with Business Objectives
Mar 14, 2022
#68 - Thought Provoking Discussions (with Richard Thieme)
Mar 07, 2022
#67 - Knock, Knock? Who’s There and Whatcha Want?
Feb 28, 2022
#66 - Working On The Supply Chain Gang
Feb 21, 2022
#65 - Shall We Play A Game?
Feb 14, 2022
#64 - 3 Keys to Being a CISO (with Allan Alford)
Feb 07, 2022
#63 - Flirting with Disaster
Jan 31, 2022
#62 - Promotion Through Politics
Jan 24, 2022
#61 - Presentation Skills
Jan 17, 2022
#60 - CISO Knowledge Domains Part 2
Jan 10, 2022
#59 - CISO Knowledge Domains Part 1
Jan 03, 2022
#58 - Active Directory is Active with Attacks
Dec 27, 2021
#57 - Brace for Audit
Dec 20, 2021
#56 - Say Firewall One More Time
Dec 13, 2021
#55 - I have more Agents than the FBI
Dec 03, 2021
#54 - The Great Resignation
Nov 19, 2021
#53 - Fun and Games to Stop Bad Actors (with Dr. Neal Krawetz)
Nov 05, 2021
#52 - Welcome to the C-Level (with Nate Warfield)
Oct 29, 2021
#51 - New Kid in Town (with Rebecca Mossman)
Oct 18, 2021
#50 - Border Gateway Protocol (BGP)
Oct 11, 2021
#49 - Cyberlaw Musings (with Mark Rasch)
Oct 01, 2021
#48 - Effective Meetings
Sep 24, 2021
#47 - More Risky Business with FAIR
Sep 17, 2021
#46 - Crisis Leadership with G Mark Hardy‘s 9/11 Experience
Sep 10, 2021
#45 - Protecting your Crown Jewels (with Roselle Safran)
Sep 03, 2021
#44 - Intro to Docker Containers and Kubernetes (K8s)
Aug 27, 2021
#43 - Cyber Deception (with Kevin Fiscus)
Aug 20, 2021
#42 - Third Party Risk Management (with Scott Fairbrother)
Aug 13, 2021
#41 - Got any Threat Intelligence?
Aug 06, 2021
#40 - Risky Business
Aug 01, 2021
#39 - Stressed Out? Find your Ikigai and 6 Invaluable Factors
Jul 23, 2021
#38 - CMMC and Me
Jul 18, 2021
#37 - Cyber Security Laws & Regulations
Jul 09, 2021
#36 - IPv6 Your Competitive Advantage (with Joe Klein)
Jul 03, 2021
#35 - Setting Up an Application Security Program
Jun 25, 2021
#34 - Metrics that Matter
Jun 18, 2021
#33 - 10 Steps to Cyber Incident Response Playbooks
Jun 11, 2021
#32 - Brace for Incident (with Bryan Murphy)
Jun 04, 2021
#31 - Executive Order on Improving the Nation’s Cybersecurity
May 28, 2021
#30 - Cloud Drift (with Yoni Leitersdorf)
May 21, 2021
#29 - Identity and Access Management is the New Perimeter
May 14, 2021
#28 - AI and ML and How to Tell When Vendors Are Full of It
May 08, 2021
#27 - Roses, Buds, & Thorns
May 01, 2021
#26 - Blockchain for CISOs
Apr 23, 2021
#25 - Slay the Dragon or Save the Princess?
Apr 16, 2021
#24 - Everything you wanted to know about Ransomware
Apr 08, 2021
#23 - NSA’s Top 10 Cybersecurity Mitigation Strategies
Apr 02, 2021
#22 - Modern Software Development Practices
Mar 26, 2021
#21 - Your First 90 Days as a CISO (with Mark Egan)
Mar 19, 2021
#20 - Zero Trust
Mar 12, 2021
#19 - Team Building
Mar 05, 2021
#18 - Executive Presence
Feb 26, 2021
#17 - Global War on Email
Feb 19, 2021
#16 - The Essential Eight
Feb 12, 2021
#15 - IT Governance
Feb 05, 2021
#14 - How to Compare Software
Jan 29, 2021
#13 - Executive Competencies
Jan 22, 2021
#12 - The Three Ways of DevOps
Jan 15, 2021
#11 - Cryptography
Jan 08, 2021
#10 - Securing the Cloud
Jan 01, 2021
#9 - Introduction to the Cloud
Dec 25, 2020
#8 - Crucial Conversations
Dec 18, 2020
#7 - DevOps
Dec 11, 2020
#6 - Change Management
Dec 04, 2020
#5 - Cyber Frameworks
Nov 27, 2020
#4 - Asset Management
Nov 20, 2020
#3 - How to Read Your Boss
Nov 13, 2020
#2 - Principles of Persuasion
Nov 06, 2020
#1 - What is a CISO?
Oct 30, 2020