We'll Worry About Recovering From the Attack Once We Ace This Audit

We'll Worry About Recovering From the Attack Once We Ace This Audit

Author: David Spark, Mike Johnson, and Andy Ellis July 22, 2025 Duration: 43:23

All links and images can be found on CISO Series.

This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis (@csoandy), partner, YL Ventures. Joining us is Peter Clay, CISO, Aireon.

In this episode:

  • Purple teaming evolution misses operational realities
  • Effective postmortems require systematic failure analysis
  • Risk expertise requires business context over methodology
  • Compliance and resilience serve different purposes

Huge thanks to our sponsor, Safe Security

SAFE is reinventing Third-Party Risk Management with Agentic AI. Our AI Agents automate onboarding, assessments, and monitoring—giving security teams real-time visibility and zero-effort control across their vendor ecosystem. See why SAFE is the fastest-growing TPRM platform on the market at https://testdrive.safe.security/.


Hosted by David Spark, Mike Johnson, and Andy Ellis, the CISO Series Podcast digs into the often complex, sometimes contentious, but always critical relationships that define modern cybersecurity. This isn't a lecture from a lone expert; it's a conversation built on the real-world friction and collaboration between the security teams who implement solutions and the vendors who create them. Each episode moves beyond theory to explore the practical mechanics of how these groups can actually work together more effectively. You'll hear frank debates, tactical advice, and shared stories that reveal what truly improves security posture for organizations of all sizes. The discussions are grounded in the daily challenges and strategic decisions faced by practitioners, offering listeners a unique, dual-perspective on the technology and news shaping the industry. Tune into this podcast for an unvarnished look at the partnerships that build stronger defenses, proving that better security is ultimately a team effort forged through open dialogue and shared goals.
Author: Language: English Episodes: 100

CISO Series Podcast
Podcast Episodes
Our Theoretical Controls Work Great Against Hypothetical Attacks [not-audio_url] [/not-audio_url]

Duration: 43:12
Our Theoretical Controls Work Great Against Hypothetical Attacks All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis, principal of Duha. J…
Why Highlight Diversity When We Can Just Hope You Don't Notice? [not-audio_url] [/not-audio_url]

Duration: 38:26
All links and images can be found on CISO Series. This week's episode is hosted by David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining is Julie Myerholtz, CISO, Brunswick Corporation. In this epi…
They're Less "Best Practices" and More "Sounds Good on LinkedIn" [not-audio_url] [/not-audio_url]

Duration: 41:54
All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining us is Rebecca Harness, CISO, Deltek. In this episode:…
Our Security Team's Love Language is Buying New Tools [not-audio_url] [/not-audio_url]

Duration: 41:22
All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining us is our sponsored guest, Tim Leehealey, vp of corpo…
If We Can't Do Better, at Least Do It Faster [not-audio_url] [/not-audio_url]

Duration: 41:37
All links and images can be found on CISO Series. This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining them is Vikas Mahajan, vp and CISO, American Red Cross. I…