In this episode of Defense In Depth podcast, David Spark, Allan Alford and I discussed: A security professional announces a new position as CISO. As a vendor you see this as good timing to try a cold outreach to sell your product. Why do so many vendors think this is a good tactic, when in reality it’s exactly what you should not do? and It all started because of this post I shared on LinkedIn
Defense in Depth podcast: When Vendors Pounce on New CISOs
The Cyber ranch podcast: What We’re Doing Wrong in the SOC
Allan Alford and I met on the at the Cyber Security Ranch podcast to talk about the SOC and why we are going about it all wrong. We identify and examine the three main areas of concern: the data, the analyst, the analysis – and how to improve upon them. I shared some thoughts with Allan on what steps and approaches need to be taken in order to successfully accomplish the SOC’s goal.
WSJ Pro cybersecurity: scoring board
Successful chief information security officers are effective at getting their message across to the board. In this session I joined Rob Sloan , WSJ Research Director, and Tim Rohrbaugh, CISO at JetBlue, where we presented to a board member and have Dr. Anastassia Lauterbach critique our efforts. It was a fun conversation.
CISO series podcast: Click This Link to Fail a Phishing Test
Our phishing tests are designed to make you feel bad about yourself for clicking a link. We’re starting to realize these tests are revealing how insensitive we are towards our employees, and the resentment and shame a phishing test can create.
I had the honor to be a guest on this episode hosted by David Spark (@dspark), producer of the CISO Series Podcast and Mike Johnson.
Cyber security leadership podcast: fear
Fear is one of the seven universal emotions experienced by everyone around the world. Fear arises with the threat of harm, either physical, emotional, or psychological, real or imagined. In this episode of the Cyber Security Leadership podcast, Jeff Snyder and I discuss whether we have too much fear in business and in the cyber security practice.
Cyber security leadership podcast: Authenticity
In this episode of the Cyber Security Leadership podcast, Jeff Snyder and I discuss authenticity and what does it mean for a leader to be authentic. Being authentic means that you act in ways that show your true self and how you feel. Rather than showing people only a particular side of yourself, you express your whole self genuinely. That means to succeed in being authentic, you first have to...
Cyber security leadership podcast: Tell less, ask more
Almost every CISO was asked during the job interview or right when they started, what will you do in your first 90 days? Many CISOs are ready to jump headfirst and tell the organization what needs to be done! Is that wise? Is there a better way?In this episode Jeff Snyder and I are joined by David Lam, the author of the book: “The New IQ: Leading Up, Down, and Across Using Innovative...
Cyber security leadership podcast: Impulse control
We’ve all been in situations at work where we secretly wish we could tell someone exactly what we think about them, or worse we had to fight an urge to go across the table and smack them over the head. While this type of reaction would have satisfied us in the moment, the long terms affects may be severe, hence we need Impulse Control. Where impulses are coming from, how do we control them, and...
WSJ Pro Cybersecurity Webinars: Preparing for Ransomware
I had the honor to be interviewed for the Wall Street Journal (WSJ) Pro Cybersecurity forum by Rob Sloan, Research Director, about how organizations prepare for Ransomware attacks.
Cyber Security Leadership Podcast: Do security professionals need to have emotional intelligence?
An emotionally intelligent individual is both highly conscious of his or her own emotional states as well as others, and is able to identify and manage them. What does it mean to have emotional intelligence in practice? Can it be thought? In this episode of the Cyber Security Leadership podcast, Jeff Snyder and I discuss why security professionals need to have emotional intelligence.