We Checked the "Yes" Box for Cybersecurity. What Else Do We Have to Do?

We Checked the "Yes" Box for Cybersecurity. What Else Do We Have to Do?

Author: David Spark, Mike Johnson, and Andy Ellis June 17, 2025 Duration: 41:24

All links and images can be found on CISO Series.

This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), partner, YL Ventures. Joining us is Alex Hall, CISO, Gensler.

In this episode:

  • Evaluating secure messaging beyond the app
  • Reframing compliance as a business enabler
  • Incremental security investment vs. crisis response
  • Why culture, not punishment, drives secure behavior

Huge thanks to our sponsor, Vanta

Automate, centralize, & scale your GRC program with Vanta
Vanta's Trust Management Platform automates key areas of your GRC program—including compliance, internal and third-party risk, and customer trust—and streamlines the way you gather and manage information. And the impact is real: A recent IDC analysis found that compliance teams using Vanta are 129% more productive. Get started at Vanta.com/ciso.

 


Hosted by David Spark, Mike Johnson, and Andy Ellis, the CISO Series Podcast digs into the often complex, sometimes contentious, but always critical relationships that define modern cybersecurity. This isn't a lecture from a lone expert; it's a conversation built on the real-world friction and collaboration between the security teams who implement solutions and the vendors who create them. Each episode moves beyond theory to explore the practical mechanics of how these groups can actually work together more effectively. You'll hear frank debates, tactical advice, and shared stories that reveal what truly improves security posture for organizations of all sizes. The discussions are grounded in the daily challenges and strategic decisions faced by practitioners, offering listeners a unique, dual-perspective on the technology and news shaping the industry. Tune into this podcast for an unvarnished look at the partnerships that build stronger defenses, proving that better security is ultimately a team effort forged through open dialogue and shared goals.
Author: Language: English Episodes: 100

CISO Series Podcast
Podcast Episodes
How About This? Only Attack the Endpoints We Configured [not-audio_url] [/not-audio_url]

Duration: 40:19
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining us…
The Post-it Note Clearly Says "Don't Share" Right Under My Password [not-audio_url] [/not-audio_url]

Duration: 37:19
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is our sponsored guest, Al…
Who You Gonna Call? LEGAL COUNSEL! [not-audio_url] [/not-audio_url]

Duration: 37:53
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining us…
Ransomware? Why'd It Have to Be Ransomware? (Live in San Francisco) [not-audio_url] [/not-audio_url]

Duration: 44:03
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is Steve Zalewski, co-host…
You Can't Leak What You Don't Collect [not-audio_url] [/not-audio_url]

Duration: 34:30
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining us…
Our Help Desk Plaque Reads "Over 100,000 Threat Actors Served" [not-audio_url] [/not-audio_url]

Duration: 35:48
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), operating partner, YL Ventures. Joining us…
I Really Shouldn't Have Agreed to Variable Rate Technical Debt [not-audio_url] [/not-audio_url]

Duration: 35:54
All links and images for this episode can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Mike Johnson, CISO, Rivian. Joining me is our sponsored guest, Aa…

«1...678910