DiscoverCISO Stories Podcast (Video)
CISO Stories Podcast (Video)
Claim Ownership

CISO Stories Podcast (Video)

Author: SC Media

Subscribed: 3Played: 24
Share

Description

SC Media and F5 are proud to present this month's CISO Stories program, where CISOs share tales from the trenches and unpack leadership lessons learned along the way. Hosted by Jessica Hoffman.
88 Episodes
Reverse
Vulnerability management isn't just about finding more vulnerabilities—it's about knowing what matters and having the resources to act. Chuck Loring of the Lee County Clerk of Circuit Court & Comptroller joins CISO Stories to explore how budgets, staffing, legacy technology, and mission priorities shape vulnerability management across the public and private sectors. We challenge the idea that AI alone will solve the problem and discuss where it can actually make a difference. Chuck shares his perspective on risk-based prioritization as vulnerability volumes continue to surge. The conversation also examines what public and private organizations can learn from each other. Ultimately, effective vulnerability management isn't about patching everything—it's about identifying and addressing what poses the greatest risk. Segment Resources: https://cybersecconsultingleaders.com/blog Show Notes: https://cisostoriespodcast.com/csp-228
In this episode of CISO Stories, Jessica Hoffman sits down with Matt Lee to explore attack surface management, AWS security, and the cloud misconfigurations that can put organizations at risk. Matt shares lessons from his experience auditing cloud environments, including common AWS security gaps around identity and access management, exposed resources, security groups, and overly permissive access. The conversation also covers emerging challenges around AI agents, protecting production data, and balancing speed of innovation with security controls. From preventing cloud breaches to building stronger security practices, Matt breaks down what organizations should understand about reducing risk in today's evolving threat landscape. Segment Resources: https://schematical.com/techdebt https://www.oreilly.com/videos/zero-to-hero/0642572107789/ https://schematical.com/posts https://schematical.com/free https://schematical.com/speaking This segment is sponsored by Horizon3. Visit https://cisostoriespodcast.com/horizon3 to learn more about them! Show Notes: https://cisostoriespodcast.com/csp-227
AI is changing cloud security fast, but the biggest challenge is not just adoption. It is governance. In this episode, Jess sits down with Brent Neil, CISO at RapidScale, to talk about what CISOs should be watching as AI becomes embedded in cloud environments, business workflows, and sensitive data systems. Brent shares practical insight on AI governance, identity and access, cloud security controls, and the risks that emerge when experimentation moves into production. The conversation explores how security leaders can support innovation without losing visibility, accountability, or trust. Brent also breaks down the questions CISOs should be asking before AI tools scale deeper into the enterprise. Because AI may be unavoidable, but unmanaged AI risk is optional. Segment Resources: RapidScale's IT Talent Gap Report: https://try.rapidscale.net/the-talent-gap/ This segment is sponsored by Arctic Wolf. Visit https://cisostoriespodcast.com/arcticwolf to learn more about them! Show Notes: https://cisostoriespodcast.com/csp-226
In this episode, former FBI cyber leader Jason Manar joins us to unpack the state of critical infrastructure security and why small and medium-sized businesses are more connected to it than they realize. From power, telecom, healthcare, finance, and supply chains, Jason explains how hidden dependencies can turn "not our problem" into a business-stopping event. With his FBI perspective and CISO experience, Jason shares what organizations should understand about risk, resilience, and protecting the systems we all quietly rely on. Show Notes: https://cisostoriespodcast.com/csp-225
Identity and access management is often sold as a technical problem, but real-world deployments tell a different story. For MSSPs managing access across multiple client environments, IAM becomes a test of trust, accountability, decision fatigue, and human behavior. In this episode of CISO Stories, we explore why access reviews become rubber stamps, why least privilege is harder than it sounds, and how cognitive bias can quietly shape security decisions. We also dig into the uncomfortable question: when organizations outsource IAM, are they outsourcing control — or just the labor? Because in the end, identity is not just about who gets access. It is about who owns the risk when access goes wrong. Show Notes: https://cisostoriespodcast.com/csp-224
loading
Comments