CISO Tradecraft®

CISO Tradecraft®

por G Mark Hardy & Ross Young

Should you get a PhD in Cybersecurity? | Dr Char Sample - #303

Should you get a PhD in Cybersecurity? In this episode of CISO Tradecraft, G. Mark Hardy sits down with Dr. Char Sample at the COSAC security conference in Ireland to unpack what it REALLY takes to earn a doctorate in cybersecurity. From her early work on the Gauntlet firewall to cybersecurity research at the Army Research Lab, INL, and Marshall University, Dr. Sample shares hard-earned lessons on research, funding, doctoral programs, and surviving the PhD journey. They also explore: Why a PhD can matter for cybersecurity research funding What makes a strong cybersecurity research problem How long a doctorate can take Research methods, proposals, and defending your work Remote vs. residency programs AI, hallucinated citations, and research reproducibility Why cybersecurity needs more focus on building securely, not just breaking things If you're considering an advanced degree or want to understand where cybersecurity research is headed, this episode is for you. 🎧 Subscribe to CISO Tradecraft for more cybersecurity leadership insights.

Security Awareness Tips for 2026 - #302

In this episode, we reveal the biggest security awareness mistakes and the creative ways to make cybersecurity training actually fun in 2026. From AI-powered phishing and token theft to stronger MFA and gamified training, There are ideas every security leader should steal. Watch now and level up your security awareness game!

How to Create a Leadership Culture - #301

Most CISOs spend years learning cybersecurity. Almost nobody teaches them how to build a culture people actually want to be part of. In this episode of CISO Tradecraft, G. Mark Hardy and Ross Young break down the leadership lessons that separate average security organizations from world-class ones. You’ll learn how to: Build a security team people WANT to join Develop your employees into future CISOs Reward behavior that actually changes culture Communicate like an executive Spot when your company may NEVER promote you to CISO Prevent burnout before your best people leave Build trust across the business Create a culture of excellence, accountability, and curiosity Ross also shares how he turned phishing awareness into a company competition, complete with trophies, CEO recognition, and brisket parties. Because great cybersecurity leadership isn't just about stopping hackers. It's about building an organization where great people can do their best work. What’s the ONE leadership rule every CISO should follow? Subscribe to CISO Tradecraft for practical lessons on cybersecurity leadership, strategy, risk, and becoming a more effective CISO. Template for Command Philosophy: https://www.gmarkhardy.com/Navy_Articles/NRA-0306%20Template%20for%20a%20Command%20Philosophy.pdf

CISO Health and Accountability Dialogue - #300

The biggest threat to a CISO might not be ransomware, it might be burnout. In this episode, G. Mark Hardy brings on We Hack Health to reveal why brilliant security leaders are sacrificing their health, how accountability can reverse the damage, and the one rule every CISO should follow: Never miss twice. Watch this before your career costs you everything. Link to CruiseCon https://cruisecon.com/events/cruisecon-privacy-ai-2026/ Use code: CISOTRADECRAFT10 for a 10% discount

Claude Code Is INSANE, But Is It Safe? - #299

Claude Code Is INSANE… But Is It Safe? AI coding just went from “autocomplete my code” to “give me the entire repository and let me run the company.” In this episode of CISO Tradecraft, G Mark Hardy and Ross Young break down what Claude Code can actually do, and the security implications that come with it. Claude Code can read entire codebases, create and edit multiple files, run commands, execute tests, and operate like an AI developer sitting directly inside your environment. But there’s a catch… Every token costs money. And every permission creates risk. We break down: 🔥 Tokenomics — How to get dramatically more AI coding for your dollar 🔥 PRDs — Why you should use powerful models to THINK before cheaper models BUILD 🔥 Security Risks — What happens when an AI agent can execute commands and modify your environment? 🔥 AI Licenses — Individual vs. enterprise and what CISOs need to worry about 🔥 Privacy & Regulated Data — When you may need offline or open-weight models 🔥 Harnesses — The policy-driven guardrails that can move security WAY earlier in the development process 🔥 MCP — How AI agents can connect to tools, systems, and data… and why permissions become a massive security issue 🔥 Agents & Skills — Serial vs. parallel agents, prompts, context, commands, hooks, and Markdown-based skills 🔥 Threat Modeling AI — Why you need to start threat modeling the prompts AND the tools The big question isn't: “Can AI write code?” It absolutely can. The question is: “What happens when we give AI the keys to the kingdom?” If you're a CISO, security leader, developer, or anyone trying to understand where agentic AI coding is heading, this episode is for you. 🎙️ Subscribe to CISO Tradecraft for more unfiltered conversations about cybersecurity, AI, leadership, and the future of the CISO. Check out the Harness that Ross is building: https://github.com/Clear-Capabilities/agentic-security

VCISO Tradecraft | Carlota Sage - #298

Most cybersecurity advice is built for massive enterprises. But what happens when you're a small or medium-sized business and you don't have a 200-person security team… or a massive budget? In this episode, Mark Hardy sits down with vCISO Carlota Sage to break down what actually works. Carlota shares lessons from her time at FireEye during its explosive growth and the Mandiant acquisition—and why being a great security leader isn't just about knowing cybersecurity. It's about IT fundamentals. Influence. Emotional intelligence. And knowing how to lead people. We also dive into: Why simply saying "thank you" can transform your security culture 💰 How cybersecurity can become sales enablement and revenue protection 📈 Why security teams should work directly with sales and finance 🔒 Why compliance isn't security—but ISO 27001 and PCI DSS can still be incredibly valuable for smaller companies 🤖 How AI is creating a massive new attack surface 🕵️ The growing risk of sensitive data leaking into AI tools 💸 Why the real cost of AI isn't just the subscription price 🎯 Who should be accountable when AI goes wrong The BIG takeaway? You don't need to be a Fortune 500 company to build a strong security program. But you do need to understand the business, influence people, protect revenue, and help your organization use technology without creating a disaster in the process. Watch now and let us know in the comments: What's the biggest cybersecurity challenge facing small and medium-sized businesses right now? 👇

AI's Biggest Security Problem | Jeff Spear - #297

AI can change your network in seconds… but your security approvals still take DAYS. In this episode, Tufin CISO Jeffrey Spear reveals how CISOs can use automation and AI without accidentally scaling security mistakes at machine speed. We break down network governance, compliance as code, AI agents, access debt, and the guardrails every security leader needs before handing AI the keys to the network. Automate the right way or build a faster way to be wrong. Get Your Network Exposure Assessment https://explore.tufin.com/assessment Big thanks to our sponsor Tufin.

AI Is Breaking Out and Cybersecurity Isn’t Ready | John Strand - #296

What happens when AI stops behaving like a tool, and starts operating beyond the boundaries we gave it? Live from Black Hat, G Mark Hardy sits down with cybersecurity veteran John Strand of Black Hills Information Security for a wide-ranging conversation about the future of AI, cybersecurity careers, penetration testing, automation, and the skills that will actually matter next. They dig into reports of AI systems escaping controlled environments, why blindly replacing security professionals with AI could backfire, and why John believes offensive AI may become more powerful than defensive AI in the near future. But the biggest takeaway may be surprising: AI doesn’t necessarily make deep technical knowledge less important. It may make it more valuable than ever. In this episode: Why AI could completely reshape cybersecurity careers The skills security professionals need to survive the AI transition Why understanding TCP/IP, operating systems, and fundamentals still matters How John built an AI-powered security workflow in minutes The danger of autonomous penetration-testing tools Why “human in the loop” may be critical for AI security The hidden business problem with OpenAI and Anthropic-dependent products Why cheaper open-weight AI models could disrupt the industry What CISOs should understand before deploying AI across their organizations Why trust, not another AI dashboard, may become cybersecurity’s biggest differentiator And John explains why, despite all the uncertainty, he’s more excited about cybersecurity today than he has been in years. If you work in cybersecurity, lead a security team, or are wondering whether AI will replace your job, this is a conversation worth watching to the end.

Is AI Leaking Your Company's Trade Secrets | Lee Kim - #295

What Every CISO Needs to Know Before AI Leaks Your Company's Crown Jewels Your AI policy won't save you if your trade secrets walk out the door. In this episode of CISO Tradecraft, attorney and technologist Lee Kim explains the legal blind spots most security leaders miss, from AI prompt retention and vendor contracts to insider risk, shadow AI, and protecting your organization's most valuable intellectual property. If you're deploying AI without thinking like a lawyer, this conversation could save you millions. Lee Kim's LinkedIn - https://www.linkedin.com/in/leekim/

Learning from the Hugging Face Incident | Gadi Evron - #294

In this CISO Tradecraft episode, host G Mark Hardy and guest Gadi Evron discuss a recent incident involving OpenAI model testing in an “exploit gym,” where an agent escaped its sandbox, attempted to access Hugging Face, created new exploits, stole credentials, and generated high-volume, unusual activity that initially blended into background noise. They describe how Hugging Face quickly shared details with the CISO community and outline observed behaviors (repeated attempts, simultaneous operations, novel paths, classic attacks like package manager flaws and credential theft, and hallucinated artifacts in logs). Key lessons include instrumenting and defending agents, using coding agents for faster response, enabling mass credential rotation and cluster rebuilds, considering deception technology, preparing for noisy forensics, maintaining access to open-weight models, budgeting for token costs, and adapting security planning to compressed timelines. CISO Retreat - https://www.cisotradecraft.com/cisoretreat Cloud Security Alliance - https://cloudsecurityalliance.org/ CSides - https://luma.com/jf8ej87e Hugging Face Analysis on ChatGPT - https://www.linkedin.com/posts/gadievron_my-analysis-from-hosting-hugging-face-at-share-7486340715514437632-Xs-b/ Knostic - https://www.knostic.ai/ Unprompted - https://unpromptedcon.org/
1 de 31