CISO Tradecraft® cover art

CISO Tradecraft®

CISO Tradecraft®

By: G Mark Hardy & Ross Young
Listen for free

About this listen

You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level.

© Copyright 2025, National Security Corporation. All Rights Reserved

© Copyright 2025, National Security Corporation. All Rights Reserved
Career Success Economics
Episodes
  • #279 - AI Readiness (with JP Bourget)
    Apr 13 2026

    On CISO Tradecraft, host G Mark Hardy welcomes back JP Bourgeet to discuss what “AI readiness” means for organizations, framing it as both a data governance challenge and a change-management problem. JP defines readiness for CISOs as strong threat protection, data security/governance, and device management, with the biggest gaps typically in labeling, DLP/DSPM, and poor information architecture (e.g., commingled data in SharePoint/Drive). They cover re-architecting past and future data into role-based structures so Copilot can honor permissions and sensitivity labels, plus the value of visibility, auditability, and insider-risk alerting for file access and LLM prompts. JP also discusses agentic systems and upcoming identity challenges for AI agents, compares AI readiness to platform engineering, emphasizes use-case-driven adoption (lunch-and-learns and ROI tracking), and highlights Daniel Miessler’s personal AI infrastructure work and a future shift toward AI-driven security products.

    JP Bourget's Website https://www.bluecycle.net/

    JP Bourget's Linkedin https://www.linkedin.com/in/jpbourget/

    SaltCon- https://naclcon.com/

    Show More Show Less
    44 mins
  • #278 - RSAC Takeaways: AI SOC, Agent Security, and What Cyber Marketing Gets Wrong
    Apr 7 2026

    In this CISO Tradecraft episode, G Mark Hardy, Ross Young, and Andy Ellis share RSAC insights from the vendor floor, including Andy’s effort to visit about 607 booths. They highlight dominant themes like AI SOC offerings and agentic/agent security messaging, noting that many booths used unclear marketing or even failed to describe what they do. The discussion critiques activity-based metrics like badge scans, arguing for outcome-focused goals such as awareness, qualified follow-ups, and customer-driven product feedback. They explore how marketing should create informed buyers, how startups should communicate problem, urgency, and differentiation, and how AI and “vibe coding” may pressure vendor pricing or encourage internal tool-building. The episode also covers open-source sustainability and recommends networking via both major conferences and smaller private CISO events.

    Take a look at these three helpful RSAC Reviews:

    DUHA - https://www.duha.co/reports/state-of-security-vendors-rsac-2026/

    VibeCoded - https://vibecoded.vc/cooked/

    Jake Epstein's RSA 2026 Startup Landscape - https://jakee.vc/rsa-2026-landscape.html

    Show More Show Less
    45 mins
  • #277 - From SaaS to AI Agents: Gone in 60 Seconds
    Mar 30 2026

    In this CISO Tradecraft episode, co-hosts G Mark Hardy and Ross Young discuss how large language models are transforming software development and shifting cybersecurity from buying Software as a Service to “Service as Software,” and ultimately to "Systems of AI agents". They explain how writing code in English enables rapid prototyping, changing cost models by reducing labor hours and increasing speed and scale, with metrics like shrinking a 40-hour threat model effort to a 10-minute agent output. Ross outlines three generations, SIEM (SaaS), SOAR (services as software), and systems of agents (AI SOC), highlighting broader, evolving detection coverage. They cover risks including underestimated maintenance, scope creep, automating bad processes, and insecure AI-generated code, and demo a prompt-built software composition analysis/SBOM tool using CycloneDX and OSV. Ross also introduces his company, Clear Capabilities, focused on agentic workforce automation for governance, privacy, architecture, and compliance.

    Cybersecurity's Dirty Secret: Why Most Budgets Go To Waste - https://www.amazon.com/Cybersecuritys-Dirty-Secret-Budgets-Tradecraft%C2%AE/dp/B0G26WHVTG/

    Ross Young -

    https://www.linkedin.com/in/mrrossyoung/

    Developer AI Threats -

    https://threats.backslash.security/

    Show More Show Less
    40 mins
No reviews yet
In the spirit of reconciliation, Audible acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.