Skip to content
Artwork for CISO Tradecraft®
TechnologyExplicit

CISO Tradecraft®

G Mark Hardy & Ross Young

You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level.

© Copyright 2025, National Security Corporation. All Rights Reserved

Play
  • 22 episodes
  • weekly
  • Avg 43 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • #298
    Tuesday · 42 min

    VCISO Tradecraft | Carlota Sage - #298

    Most cybersecurity advice is built for massive enterprises. But what happens when you're a small or medium-sized business and you don't have a 200-person security team… or a massive budget? In this episode, Mark Hardy sits down with vCISO Carlota Sage to break down what actually works. Carlota shares lessons from her time at FireEye during its explosive growth and the Mandiant acquisition—and why being a great security leader isn't just about knowing cybersecurity. It's about IT fundamentals. Influence. Emotional intelligence. And knowing how to lead people. We also dive into: Why simply saying "thank you" can transform your security culture 💰 How cybersecurity can become sales enablement and revenue protection 📈 Why security teams should work directly with sales and finance 🔒 Why compliance isn't security—but ISO 27001 and PCI DSS can still be incredibly valuable for smaller companies 🤖 How AI is creating a massive new attack surface 🕵️ The growing risk of sensitive data leaking into AI tools 💸 Why the real cost of AI isn't just the subscription price 🎯 Who should be accountable when AI goes wrong The BIG takeaway? You don't need to be a Fortune 500 company to build a strong security program. But you do need to understand the business, influence people, protect revenue, and help your organization use technology without creating a disaster in the process. Watch now and let us know in the comments: What's the biggest cybersecurity challenge facing small and medium-sized businesses right now? 👇

  • #297
    August 17 · 40 min

    AI's Biggest Security Problem | Jeff Spear - #297

    AI can change your network in seconds… but your security approvals still take DAYS. In this episode, Tufin CISO Jeffrey Spear reveals how CISOs can use automation and AI without accidentally scaling security mistakes at machine speed. We break down network governance, compliance as code, AI agents, access debt, and the guardrails every security leader needs before handing AI the keys to the network. Automate the right way or build a faster way to be wrong. Get Your Network Exposure Assessment https://explore.tufin.com/assessment Big thanks to our sponsor Tufin.

  • #296
    August 10 · 44 min

    AI Is Breaking Out and Cybersecurity Isn’t Ready | John Strand - #296

    What happens when AI stops behaving like a tool, and starts operating beyond the boundaries we gave it? Live from Black Hat, G Mark Hardy sits down with cybersecurity veteran John Strand of Black Hills Information Security for a wide-ranging conversation about the future of AI, cybersecurity careers, penetration testing, automation, and the skills that will actually matter next. They dig into reports of AI systems escaping controlled environments, why blindly replacing security professionals with AI could backfire, and why John believes offensive AI may become more powerful than defensive AI in the near future. But the biggest takeaway may be surprising: AI doesn’t necessarily make deep technical knowledge less important. It may make it more valuable than ever. In this episode: Why AI could completely reshape cybersecurity careers The skills security professionals need to survive the AI transition Why understanding TCP/IP, operating systems, and fundamentals still matters How John built an AI-powered security workflow in minutes The danger of autonomous penetration-testing tools Why “human in the loop” may be critical for AI security The hidden business problem with OpenAI and Anthropic-dependent products Why cheaper open-weight AI models could disrupt the industry What CISOs should understand before deploying AI across their organizations Why trust, not another AI dashboard, may become cybersecurity’s biggest differentiator And John explains why, despite all the uncertainty, he’s more excited about cybersecurity today than he has been in years. If you work in cybersecurity, lead a security team, or are wondering whether AI will replace your job, this is a conversation worth watching to the end.

  • #295
    August 3 · 45 min

    Is AI Leaking Your Company's Trade Secrets | Lee Kim - #295

    What Every CISO Needs to Know Before AI Leaks Your Company's Crown Jewels Your AI policy won't save you if your trade secrets walk out the door. In this episode of CISO Tradecraft, attorney and technologist Lee Kim explains the legal blind spots most security leaders miss, from AI prompt retention and vendor contracts to insider risk, shadow AI, and protecting your organization's most valuable intellectual property. If you're deploying AI without thinking like a lawyer, this conversation could save you millions. Lee Kim's LinkedIn - https://www.linkedin.com/in/leekim/

  • #294
    July 27 · 48 min

    Learning from the Hugging Face Incident | Gadi Evron - #294

    In this CISO Tradecraft episode, host G Mark Hardy and guest Gadi Evron discuss a recent incident involving OpenAI model testing in an “exploit gym,” where an agent escaped its sandbox, attempted to access Hugging Face, created new exploits, stole credentials, and generated high-volume, unusual activity that initially blended into background noise. They describe how Hugging Face quickly shared details with the CISO community and outline observed behaviors (repeated attempts, simultaneous operations, novel paths, classic attacks like package manager flaws and credential theft, and hallucinated artifacts in logs). Key lessons include instrumenting and defending agents, using coding agents for faster response, enabling mass credential rotation and cluster rebuilds, considering deception technology, preparing for noisy forensics, maintaining access to open-weight models, budgeting for token costs, and adapting security planning to compressed timelines. CISO Retreat - https://www.cisotradecraft.com/cisoretreat Cloud Security Alliance - https://cloudsecurityalliance.org/ CSides - https://luma.com/jf8ej87e Hugging Face Analysis on ChatGPT - https://www.linkedin.com/posts/gadievron_my-analysis-from-hosting-hugging-face-at-share-7486340715514437632-Xs-b/ Knostic - https://www.knostic.ai/ Unprompted - https://unpromptedcon.org/

  • #293
    July 20 · 41 min

    Legal Developments Every CISO Needs to Know | Larry Dietz - #293

    Three major legal changes. One question every CISO should be asking: Is your cybersecurity program ready? Congress let a key FISA surveillance authority expire. The Supreme Court raised the bar on geofence warrants. The Department of Defense paused mandatory CMMC Level 2 certifications. At first glance, these seem like unrelated legal headlines. In reality, they all point to the same challenge: cybersecurity leaders must understand how changing laws affect data access, privacy, compliance, and personal liability. In this episode of CISO Tradecraft, host G. Mark Hardy sits down with attorney and cybersecurity expert Larry Dietz to break down what these legal developments actually mean for CISOs, not from a political perspective, but from a practical leadership perspective. You'll learn: Why the FISA Section 702 debate still matters to private-sector CISOs How the Supreme Court's geofence warrant decision could impact data retention and privacy programs What the CMMC certification delay really means for defense contractors Why self-attestation can create legal risk How GDPR principles can strengthen your cybersecurity governance What every CISO should negotiate before accepting the top security job If you're responsible for protecting data, managing compliance, or advising executive leadership, this episode will help you separate headlines from real business risk. Subscribe for weekly insights that help cybersecurity leaders become more effective.

  • #292
    July 13 · 41 min

    The Business Risk Playbook CISOs Use to Win - #292

    What separates great CISOs from everyone else? It isn't knowing more about CVEs, ransomware, or the latest security tools. It's understanding the business. In this episode of CISO Tradecraft, Ross Young and G Mark Hardy reveal why many cybersecurity leaders spend too much time protecting systems and not enough time protecting the capabilities that generate revenue, keep operations running, and create shareholder value. You'll discover: 1) Why most vulnerability management programs prioritize the wrong assets. 2) The six business capabilities every CISO should understand before making security decisions. 3) How executive leaders evaluate cyber risk differently than security teams. 4) A practical framework for aligning cybersecurity investments with business priorities. 5) Why traditional third-party risk questionnaires often fail—and the questions that actually predict ransomware risk. 6) Lessons learned from real-world breaches, mergers & acquisitions, business resilience, and executive decision making. Free Resources Mentioned • Ransomware Risk Assessment Questionnaire - https://drive.google.com/file/d/1L4spXwrB7nFgdSP5at2uJfFKvG_7ppmz/ • Mission-Critical Business Capability Framework - https://docs.google.com/presentation/d/1zHjxcJXvAkJNQKXCVbVoR7yzexD3KKEu

  • #291
    July 6 · 41 min

    The CISO Mind Map Has Evolved for the AI Era - #291

    How has the role of the CISO changed over the last 15 years? In this episode of CISO Tradecraft, G. Mark Hardy interviews Rafeeq Rehman, creator of the CISO Mind Map, to discuss its latest update and the biggest challenges facing cybersecurity leaders today. You'll learn: Why the CISO Mind Map was updated after 15 years How AI security is reshaping cybersecurity leadership Why the remote work category was removed How a RACI matrix helps CISOs delegate while staying accountable Why consolidating security tools reduces complexity and risk How to support your team's mental health in a high-stress industry What tomorrow's cybersecurity leaders need to succeed Whether you're an aspiring CISO or an experienced security executive, this episode provides practical insights to help you lead more effectively in the AI era. Link to the Mind Map - https://rafeeqrehman.com/2026/04/11/ciso-mindmap-2026-what-do-infosec-professionals-really-do/

  • #290
    June 29 · 41 min

    Harvest Now, Decrypt Later | Marcus Sachs - #290

    Nation-state adversaries are vacuuming up encrypted traffic today, waiting for quantum computers to decrypt it tomorrow. This attack strategy, "Harvest Now, Decrypt Later," isn't theoretical. It's happening right now. G Mark Hardy sits down with Marcus Sachs (former White House cyber advisor, CSO of NERC, now SVP and Chief Engineer at CIS) to break down two executive orders just signed by the White House on post-quantum cryptography and what every security leader needs to do before the clock runs out. What you'll learn: Why TLS, VPNs, and PKI are your most urgent exposure The Harvest Now, Decrypt Later threat model and what it means for your data retention policies How to build a Cryptographic Bill of Materials (CBOM) What cryptographic agility means and why hard-coded crypto is a ticking time bomb Lessons from Y2K that apply directly to the quantum migration You can't name a date certain. But your adversaries are already running the clock. Links, NIST resources, and both executive orders in the show notes. https://www.nist.gov/cybersecurity-and-privacy/what-post-quantum-cryptography https://www.nist.gov/pqc

  • #289
    June 22 · 43 min

    #289 - What's the Best Career Move After Being a CISO? (with Gary Hayslip)

    On this episode of CISO Tradecraft, host G Mark Hardy talks with Gary Hayslip about cybersecurity career growth beyond the traditional CISO “apex,” drawing on Hayslip’s 25+ years across military service, US Navy civil service, the City of San Diego as its first CISO, Webroot (CISO/CIO), SoftBank (including cyber and physical security), and most recently a field CISO role before being laid off. They discuss how the CISO role is evolving into merged executive positions (technology, risk, and AI), why continuous learning is essential as security changes rapidly, and why humans remain accountable even as AI reshapes teams. Hayslip outlines alternative paths like field CISO, data center security leadership, and VC/PE operating partner roles, and shares practical ways organizations used AI to speed legal review and automate security reporting while highlighting cost, risk, and workforce concerns.

  • #288
    June 15 · 39 min

    #288 - How to Break Into Cybersecurity Through GRC (with Steve McMichael)

    In this CISO Tradecraft episode, host G Mark Hardy interviews Steve McMichael, author of "How to Break into GRC: Mindset, Methods, and Skills," about entering cybersecurity through governance, risk, and compliance. McMichael shares his transition from accounting and explains GRC’s role as decision support and the interface between business and technical teams, breaking down governance, risk management, and compliance (including audits and third-party/supply-chain assurance). They discuss misconceptions that GRC is “just paperwork,” barriers like imposter syndrome, and strategies such as building T-shaped skills, targeting about 20% technical depth across domains, and developing credibility through a deep specialty. McMichael also describes an immersion mindset driven by emotional engagement, and showcases an open-source NIST Cybersecurity Framework Profile Assessment Database project on GitHub to help newcomers build skills and portfolio contributions.

  • #287
    June 8 · 45 min

    #287 - Cybersecurity Insights You'll Want to Hear (with Michael Hammer)

    Want to move from "security expert" to "trusted business leader"? Join G. Mark Hardy and Michael Hammer. The mind behind the core of DMARC, for 40 years of hard-won wisdom on navigating the CISO role, This episode is a masterclass in evolving from a technical gatekeeper to a strategic influencer who changes the environment,. Inside this episode: Modern Email Security: Why DMARC and SPF aren't "set and forget" tools and how to stop "cousin domain" attacks,. The 30-Minute Audit: Use the "Turn the Rocks Over" method to vet any vendor’s security posture in minutes. Risk vs. Ownership: Why you must ensure the executive team makes informed risk decisions, and why you should get them in writing. The AI Storm: How Mythos AI is accelerating the disclosure of years of hidden code vulnerabilities,. Stop being a "compliance tax" and start protecting revenue. Watch now to learn how to build a true security culture

  • #286
    June 1 · 45 min

    #286 - AI-Native Security (with Nishant Doshi & Saro Subbiah)

    What if your next breach isn't caused by a human... but by an AI agent acting exactly as instructed? Cyberhaven's CEO (Nishant Doshi) and SVP of Engineering (Saro Subbiah) reveal why AI is a true zero-to-one shift, why every employee is building agents, and why traditional security controls are struggling to keep up with machine-speed workflows. The most interesting question for CISOs isn't whether AI will be adopted, it's which security control breaks first when thousands of human-plus-agent workflows start operating across your enterprise? Watch the episode and weigh in: What do you believe will be the first major failure point of enterprise AI adoption, identity, code review, third-party dependencies, data security, audit trails, or something else entirely? Big thanks to our Sponsor Cyberhaven - https://www.cyberhaven.com/product

  • #285
    May 25 · 42 min

    #285 - Passwordless Authentication (with Nishant Kaushik)

    In this discussion, G. Mark Hardy and Nishant Kaushik explore the necessity of moving beyond traditional passwords, which they define as the original sin of cybersecurity due to their vulnerability to credential stuffing and phishing attacks. Kaushik explains that the FIDO Alliance promotes a passwordless future by replacing shared secrets with asymmetric cryptography, utilizing private keys stored on smartphones or hardware tokens like YubiKeys to ensure phishing-resistant authentication. The conversation highlights that identity is the new perimeter, shifting the focus from human-memorized codes to biometric verification and device-bound passkeys that verify user presence. Ultimately, the experts warn that a secure transition must include robust account recovery flows, as failing to secure the "back door" renders even the most advanced cryptographic-based authentication vulnerable to exploitation. FIDO Alliance - https://fidoalliance.org/

  • #284
    May 18 · 45 min

    #284 - Lessons Learned from SQL Slammer to AI Agents (with Aaron Turner)

    What can today’s CISOs learn from the chaos of Code Red and SQL Slammer? In this episode, G Mark Hardy interviews Aaron Turner about what it was like responding inside Microsoft during two of the most infamous cyber outbreaks in history. Aaron shares firsthand stories from the era when SQL Slammer infected at least 75,000 systems in roughly 10 minutes, exposing massive gaps in patch management, security QA, firewall design, and enterprise readiness. He explains how Microsoft’s early security culture operated, how major incidents and source-code theft forced change, and why many of the same mistakes are now reappearing in enterprise AI adoption. The conversation connects the lessons of Code Red and Slammer directly to today’s AI security challenges, including: Unauthenticated MCP servers and weak authorization models AI accelerating exploit development and vulnerability discovery Why the traditional “patching game” no longer scales The growing importance of identity security, ITDR, SASE, and developer controls How CISOs should think about technical debt and legacy modernization Why serverless and cloud-native architectures may become security necessities If you’re a CISO, deputy CISO, security architect, or aspiring security leader navigating the risks of AI-driven attacks, this episode provides practical lessons from one of the most important eras in cybersecurity history and why those lessons matter even more today. Aaron Turner's Linkedin - https://www.linkedin.com/in/aaronrturner/

  • #283
    May 11 · 47 min

    #283 - Leadership Lessons and the Art of the Performance (with Chris Brogan)

    In this episode of the CISO Tradecraft podcast, host G Mark Hardy interviews early tech adopter Chris Brogan to explore the intersection of high-performance leadership and effective communication. Drawing from his interviews with Navy SEALs and his tenure as a Chief of Staff, Brogan emphasizes that leadership is essentially the management of options and the cultivation of repetitive training to build a reliable team base. The discussion highlights the necessity of aligning staff roles with business needs, which sometimes requires the difficult but professional decision to let individuals go when they no longer fit the objective. Both experts stress that fully qualifying personnel for their next level of responsibility is a vital duty for any leader aiming for organizational excellence. Ultimately, the conversation advocates for authenticity, a willingness to fail forward, and the use of technology to foster genuine human interaction. Chris Brogan's LinkedIn - https://www.linkedin.com/in/cbrogan/

  • #282
    May 4 · 45 min

    #282 - Top 10 Agentic AI Attacks (with Rock Lambros)

    In this CISO Tradecraft episode, host G Mark Hardy interviews recovering CISO Rock Lambros (Zenity) about securing Agentic AI and the emerging risks beyond LLM hallucinations. Lambros recounts his path from Oracle developer to CISO and AI standards work, then explains how agentic AI increases risk by connecting models to tools and actions. They discuss agentic AI supply chain attacks, including backdoored LiteLLM packages on PyPI and a compromised Amazon Q update, and the resulting shift from “patch fast” to more cautious dependency controls. The conversation highlights the OWASP Top 10 for Agentic Applications 2026, covering threats like goal hijack, tool misuse, identity/privilege abuse, memory/context injection, insecure inter-agent communication, cascading failures, human trust exploitation, and rogue agents, concluding with practical steps: inventory, kill switches, least agency, intent gates, and observability. OWASP Top 10 for Agentic Applications - https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/

  • #281
    April 27 · 48 min

    #281 - SIEM Secrets They Don’t Tell You (with Anton Chuvakin & Alex Hurtado)

    In this CISO Tradecraft episode, host G Mark Hardy talks with Anton Chuvakin and Alex Hurtado about how SIEM programs fail and how organizations overspend when implementations prioritize dashboards or compliance over actionable detection engineering and collecting the right data. They share costly war stories ranging from multi-million and eight-figure deployments that became expensive “log toilets” or missed incidents due to data rationing and gaps, to mid-market teams burned by next-gen startup SIEMs going end-of-life and forcing replatforming. The discussion covers why Gartner Magic Quadrants can be useful depending on organizational context, the tradeoffs of decoupled/hybrid SIEM and security data lake architectures (cost, coverage, vendor management, and real-time detection limits), migration and egress/lock-in concerns, emerging AI/agentic SOC models and pricing, and the need to define requirements and measure effectiveness with realistic detection testing metrics.

  • #280
    April 20 · 43 min

    #280 - Mythos and the Future of Vulnerability Operations (with Gadi Evron)

    In this episode of CISO Tradecraft, host G Mark Hardy speaks with Gadi Evron about the paper “The AI Vulnerability Storm Building: A Mythos Ready Security Program,” a community-driven draft produced in days with extensive input from security leaders. Evron explains how advances in LLMs and agents are accelerating vulnerability discovery and exploitation, shrinking time-to-exploit assumptions and likely increasing the volume of real vulnerability reports and patches. They discuss separating hype from real risk, the impact of Anthropic’s Mythos and limited access via Project Glasswing, and what CISOs should do now: adopt agents to operate at machine speed, use them defensively to find issues, build “vuln ops” capabilities, secure coding agents in the enterprise, and communicate shifting risk metrics to boards. They also preview the next Unprompted conference planned for September. VulnAxis - https://vulnaxis.com/ Gadi Evron - https://www.linkedin.com/in/gadievron/ Knostic - https://www.knostic.ai/ The AI Vulnerability Storm Paper - https://labs.cloudsecurityalliance.org/mythos-ciso/ Unprompted - https://unpromptedcon.org/

  • #279
    April 13 · 44 min

    #279 - AI Readiness (with JP Bourget)

    On CISO Tradecraft, host G Mark Hardy welcomes back JP Bourgeet to discuss what “AI readiness” means for organizations, framing it as both a data governance challenge and a change-management problem. JP defines readiness for CISOs as strong threat protection, data security/governance, and device management, with the biggest gaps typically in labeling, DLP/DSPM, and poor information architecture (e.g., commingled data in SharePoint/Drive). They cover re-architecting past and future data into role-based structures so Copilot can honor permissions and sensitivity labels, plus the value of visibility, auditability, and insider-risk alerting for file access and LLM prompts. JP also discusses agentic systems and upcoming identity challenges for AI agents, compares AI readiness to platform engineering, emphasizes use-case-driven adoption (lunch-and-learns and ROI tracking), and highlights Daniel Miessler’s personal AI infrastructure work and a future shift toward AI-driven security products. JP Bourget's Website https://www.bluecycle.net/ JP Bourget's Linkedin https://www.linkedin.com/in/jpbourget/ SaltCon- https://naclcon.com/

Showing 1–20 of 22 episodes