Skip to content
video episode
0:00 / 1:06:15
The Changelog · May 14 · 1 hr 6 min

Episode 0x19 with Dominic Vogel

Viktor Petersson and Daniel Mountcastle sit down with Dominic Vogel, Founder of Vogel Cyber Leadership and Coaching and a fractional CISO, to unpack the realities of fractional CISO cybersecurity for SMBs. The conversation explores why many small and mid-sized businesses struggle with cybersecurity despite significant spending. Dominic shares firsthand experience from manufacturing and SMB environments, where legacy systems, long technology lifecycles, and limited internal expertise create unique challenges. They cover how supply chain pressure, especially from large enterprises, is forcing companies to take security more seriously, and why compliance frameworks often fail to reflect real risk. The episode also digs into practical issues operators face every day, including shadow IT, the rise of shadow AI, poor vendor incentives, and the gap between technical teams and business leadership. Effective cybersecurity, Dominic argues, is less about tools and more about visibility, prioritization, and clear communication. For teams managing infrastructure and distributed systems, this episode offers a grounded look at how to approach security as a business function, not just a technical checklist.

Play in podnod

transcript

No transcript — this publisher did not publish one.

show notes

Viktor Petersson and Daniel Mountcastle sit down with Dominic Vogel, Founder of Vogel Cyber Leadership and Coaching and a fractional CISO, to unpack the realities of fractional CISO cybersecurity for SMBs.

The conversation explores why many small and mid-sized businesses struggle with cybersecurity despite significant spending. Dominic shares firsthand experience from manufacturing and SMB environments, where legacy systems, long technology lifecycles, and limited internal expertise create unique challenges. They cover how supply chain pressure, especially from large enterprises, is forcing companies to take security more seriously, and why compliance frameworks often fail to reflect real risk.

The episode also digs into practical issues operators face every day, including shadow IT, the rise of shadow AI, poor vendor incentives, and the gap between technical teams and business leadership. Effective cybersecurity, Dominic argues, is less about tools and more about visibility, prioritization, and clear communication. For teams managing infrastructure and distributed systems, this episode offers a grounded look at how to approach security as a business function, not just a technical checklist.

more episodes

All episodes