I Don't Just Guess About Effectiveness, I Make Educated Guesses!

I Don't Just Guess About Effectiveness, I Make Educated Guesses!

Author: David Spark, Mike Johnson, and Andy Ellis November 4, 2025 Duration: 39:26

All links and images can be found on CISO Series.

This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis (@csoandy), principal of Duha. Joining us is Sara Madden, CISO, Convera.

In this episode: 

  • Optimizing for reality, not idealism
  • Engineering governance instead of monitoring compliance
  • When AI finds what humans miss
  • The measurement problem

Huge thanks to our sponsor, ThreatLocker

Human error remains one of the top cybersecurity threats. Just one wrong click can
open the door to ransomware or data loss. With ThreatLocker, unauthorized apps,
scripts, and devices are blocked before they can ever run. See how ThreatLocker can
help you gain more control over your environment. https://threatlocker.com

Hosted by David Spark, Mike Johnson, and Andy Ellis, the CISO Series Podcast digs into the often complex, sometimes contentious, but always critical relationships that define modern cybersecurity. This isn't a lecture from a lone expert; it's a conversation built on the real-world friction and collaboration between the security teams who implement solutions and the vendors who create them. Each episode moves beyond theory to explore the practical mechanics of how these groups can actually work together more effectively. You'll hear frank debates, tactical advice, and shared stories that reveal what truly improves security posture for organizations of all sizes. The discussions are grounded in the daily challenges and strategic decisions faced by practitioners, offering listeners a unique, dual-perspective on the technology and news shaping the industry. Tune into this podcast for an unvarnished look at the partnerships that build stronger defenses, proving that better security is ultimately a team effort forged through open dialogue and shared goals.
Author: Language: English Episodes: 100

CISO Series Podcast
Podcast Episodes
Our Developers' New Motto is "LLM Take the Wheel" [not-audio_url] [/not-audio_url]

Duration: 37:09
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), partner, YL Ventures. Joining us is Deneen…
4th Party Data Breach? We Can Barely Catch the 1st Party Ones! [not-audio_url] [/not-audio_url]

Duration: 37:51
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is George Finney, CISO, Th…
I Support Open Source as Long as I Don't Have to Invest in It [not-audio_url] [/not-audio_url]

Duration: 37:20
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Steve Zalewski. Joining us is our guest, Brett Perry, CISO, Dot F…
Ewww! How Long Has This Router Been in the Fridge? [not-audio_url] [/not-audio_url]

Duration: 38:52
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), partner, YL Ventures. Joining us is Yabing…
Why Bother Helping Users When We Can Complain About Them? [not-audio_url] [/not-audio_url]

Duration: 37:33
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is our sponsored guest Dan…
Can't Our Employees Just Go Back to Stealing Pens? [not-audio_url] [/not-audio_url]

Duration: 38:06
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is our sponsored guest, It…
We Take Software Security Seriously, As Long As It Ships on Time [not-audio_url] [/not-audio_url]

Duration: 34:34
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is our sponsored guest Jer…
Aww, Your Cybersecurity Concerns Are So Adorable (LIVE in La Jolla) [not-audio_url] [/not-audio_url]

Duration: 40:38
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Gary Hayslip, CISO, Softbank Investment Advisors. Joining us is K…
Once You Show Me Your Diploma, I'll Explain Why We Don't Gatekeep [not-audio_url] [/not-audio_url]

Duration: 39:47
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), partner, YL Ventures. Joining us is Jimmy…