Candid CISO Podcast cover art

Candid CISO Podcast

Candid CISO Podcast

By: Steve Tout and John Donovan
Listen for free

About this listen

Welcome to the Candid CISO podcast. Your path to impact. Illuminated.© 2024 Nonconformist Innovation Media, LLC Economics Politics & Government
Episodes
  • Leading Fearlessly in High-Growth Environments with Jimmy Sanders
    Nov 27 2024

    Send us a text

    In this episode of the Candid CISO Podcast, John Donovan sits down with Jimmy Sanders, a cybersecurity leader whose journey from interning at a beef jerky company to leading security teams at Netflix and Samsung is nothing short of inspiring. Join us as Jimmy shares his experience of leading fearlessly in high-growth environments, where the pressure to innovate never stops and the stakes are sky-high. He reveals how he balanced security and rapid development, motivated teams beyond monetary incentives, and built proactive, resilient defenses in environments where risk was a given. We also explore Jimmy's unique perspective on diversity in tech, the grit required to overcome obstacles, and his current role as International President of ISSA, where he’s shaping the future of cybersecurity leadership. Whether you’re a security professional or a business leader, this episode will provide practical insights and thought-provoking strategies to lead cybersecurity teams and programs with courage and vision.

    Key Takeaways

    • Integrate security into development in ways that accelerate innovation, making protection a catalyst rather than a constraint.
    • Harness individual intrinsic motivators to inspire your team, transforming engagement from compliance to passionate commitment.
    • Embed security as a shared objective early, ensuring risk discussions influence key decisions rather than follow them.
    • Think ahead of threats by building a culture of continuous testing, turning defense into an anticipatory advantage.
    • Align your leadership approach with organizational values to drive influence and lasting change across cultural differences.
    • Forge alliances across teams to dismantle silos, using trust as the foundation for more resilient security strategies.
    • Leverage your position to challenge status quo thinking and push for diversity that enriches the entire industry.
    • Shift from pure technical talk to storytelling and empathy, making complex security issues relatable and urgent for all.
    • Future-proof talent by immersing them in the technologies reshaping security, fostering adaptability over mere expertise.
    • Don’t just wait for doors to open; cultivate opportunities by acting decisively and positioning yourself for growth.

    IdRamp is a sponsor of the Candid CISO podcast. Visit their website at: https://www.idramp.com/candidciso

    TrustLogix is a sponsor of the Candid CISO podcast. Visit their website at: https://www.trustlogix.io/candidciso

    For show notes, transcripts, links, and more episodes visit https://www.candidciso.com

    The Candid CISO podcast is produced by Nonconformist Innovation Media.

    V2

    Support the show

    Show More Show Less
    52 mins
  • Reimagining Risk and the Virtual CISO
    Nov 6 2024

    In this insightful Candid CISO episode, John Donovan interviews Carlota Sage, a vCISO with a unique, multifaceted background in tech and cybersecurity. They discuss the strengths and challenges of the vCISO role versus full-time CISO positions, emphasizing the flexibility and affordability vCISOs bring to organizations that can't justify a full-time CISO. Carlota shares her experiences at major security conferences, the increasing role of compliance in driving security initiatives, and the critical importance of community, diversity, and boundary-setting in tech. Her candid stories reveal her journey from unconventional beginnings in tech to her current advocacy for strong security programs. This episode is particularly valuable for its real-world advice on leveraging compliance as a business enabler and the power of community and diversity in cybersecurity.

    Key Takeaways:

    • vCISOs provide flexible, high-quality security expertise – Ideal for companies needing CISO-level support without full-time costs.

    • Compliance often drives SMB security efforts – Many startups only implement security when clients or contracts require it.

    • Boundary-setting is crucial in cybersecurity – Protecting personal time preserves energy and prevents burnout in demanding roles.

    • Security as a sales enabler – Compliance readiness can differentiate startups and drive new business.

    • Community combats cybersecurity burnout – Engaging in networks like B-sides and Diana Initiative supports career longevity.

    • Diversity of thought strengthens security – Unique perspectives, not just backgrounds, drive more resilient cybersecurity programs.

    • Introverts and extroverts complement in cybersecurity – Collaboration can bring quieter, skilled professionals into the spotlight.

    • Third-party compliance impacts everyone – Big enterprises push smaller vendors to meet higher compliance standards.

    • Speaking at conferences builds visibility – Being a security speaker, even at small events, raises professional credibility.

    • Leverage security metrics for funding – Know customer acquisition costs and use them to justify security budgets.

    IdRamp is a sponsor of the Candid CISO podcast. Visit their website at: https://www.idramp.com/candidciso

    TrustLogix is a sponsor of the Candid CISO podcast. Visit their website at: https://www.trustlogix.io/candidciso

    For show notes, transcripts, links, and more episodes visit https://www.candidciso.com

    The Candid CISO podcast is produced by Nonconformist Innovation Media.

    Show More Show Less
    56 mins
  • The CISO Who Rebuilt Giants with Rinki Sethi
    Oct 25 2024

    Send us a text

    In this episode of The Candid CISO, Rinki Sethi, a trailblazing cybersecurity leader, shares her incredible journey from an unexpected start in the industry to her rise as a prominent figure in security leadership with host John Donovan. Rinki opens up about the challenges she faced, the importance of mentorship, and how vulnerability and communication have been crucial to her success. She provides insightful guidance on building strong security teams, navigating crisis management, and fostering a supportive cybersecurity community. Tune in for practical advice and inspiration for advancing your own cybersecurity career.

    Key topics include

    1. Discovering your specific passion within the broad field of cybersecurity is crucial for a fulfilling career, as Rinki Sethi’s own journey from compliance to developer training demonstrates.
    2. Mentorship can be found in unexpected places, from peers to senior leaders, and actively seeking guidance from those around you can significantly shape your career path.
    3. Securing executive buy-in is essential for building a strong security culture, and aligning security goals with business objectives helps demonstrate the value of security initiatives.
    4. To effectively advocate for security investments, it is crucial to present security as a business enabler, highlighting its ability to improve efficiency, reduce friction, and even create a competitive advantage.
    5. Sharing real-world examples of how security programs have reduced business friction, such as streamlining compliance processes or shortening sales cycles, can help garner support for future security initiatives.
    6. Transparency and clear communication are vital when implementing security programs, especially those that may be perceived as intrusive, to ensure understanding and minimize resistance.
    7. Prioritizing mental health in the demanding field of cybersecurity is crucial, and creating a supportive environment where team members feel comfortable seeking help and addressing mental well-being is essential.
    8. Crisis management exercises, including surprise breach simulations, can be invaluable for preparing executive teams and other stakeholders to effectively navigate real-world security incidents.
    9. Networking outside of your immediate professional circle can lead to unexpected mentorship opportunities, board positions, and valuable connections that can benefit your career in the long run.
    10. Giving back to the cybersecurity community by mentoring others, sharing your experiences, and encouraging newcomers is crucial for fostering a strong and inclusive industry.

    IdRamp is a sponsor of the Candid CISO podcast. Visit their website at: https://www.idramp.com/candidciso

    TrustLogix is a sponsor of the Candid CISO podcast. Visit their website at: https://www.trustlogix.io/candidciso

    For show notes, transcripts, links, and more episodes visit https://www.candidciso.com

    The Candid CISO podcast is produced by Nonconformist Innovation Media.

    Support the show

    Show More Show Less
    54 mins

What listeners say about Candid CISO Podcast

Average Customer Ratings

Reviews - Please select the tabs below to change the source of reviews.

In the spirit of reconciliation, Audible acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.