Discover
The cyber weekly
The cyber weekly
Author: Deogratius Okello, Josephine Olok and Angella Nabbanja
Subscribed: 3Played: 7Subscribe
Share
Β© Copyright 2023 All rights reserved.
Description
Dive into the world of cybersecurity, book reviews, and effective management strategies, including how to communicate with a board. If this piques your interest, join the club!
111Β Episodes
Reverse
π¨ Most CISOs can explain every control on their stack but ask them what the business actually sells, and they go quiet.
In this episode of The Cyber Weekly, Deo sits down with Jake Bernardes CISO at Gambit Security, ex-pen tester, chartered accountant, and a guy who learned Chinese and German before ever touching cybersecurity.
We get into:
π° The "Minimum Viable Business" framework for justifying security spend
π§© Why GRC is broken (and how to fix the forgotten "R")
π€ Which security roles AI will kill and which ones it can't touch
π Why Jake thinks certifications are mostly pointless
π Why your network matters more than your CISSP
ποΈ Building leadership on transparency, vulnerability, and authenticity
Β
Here the links
Random Access Memories: https://randomaccessmemories.io
Jake Bernardes on LinkedIn: https://www.linkedin.com/in/jakeleobernardes/
Random Access Memories on YouTube: https://www.youtube.com/@RandomAccessMemoriesPod
Β
If you're in GRC, trying to break into cybersecurity, or leading a security team through the AI shift this conversation will change how you think about your career.
00:00 Intro: The Intersection of Chinese & Cybersecurity
01:19 Who is Jake Bernardes?
03:18 How Accounting Creates Better CISOs
04:14 The "Minimum Viable Business" & Proving ROI
08:26 Why GRC is Broken (And How to Fix It)
13:02 The Future of GRC Engineering & Automation
17:32 Why Cyber Certifications Are "Pointless"
19:24 AI is Killing Tier 1 SOC Jobs: What to do next
22:43 The 3 Pillars of True Leadership
#TheCyberWeekly #CISO #Cybersecurity #GRC #RiskManagement #CyberCareers #InfoSec #CyberLeadership πποΈπ
In this episode of The Cyber Weekly Podcast, hosts Deogratius Okello and Angella Nabbanja sit down with MΔdΔlin Bratu β General Manager and Founder of Sectio Aurea (operating under the brand Phi). MΔdΔlin brings 20 years of experience across cybersecurity, governance, risk, and enterprise technology, sharing insights from his career at IBM, CA Technologies, and Eviden/Atos. He breaks down the realities of implementing frameworks like NIS2 and ISO 27001 in complex operational environments, why compliance must move beyond "paperwork security," and how he utilizes the expert-network model to deliver real-world security solutions. Whether you're starting out in GRC or looking to build your own consultancy, this conversation is packed with hard-earned lessons on compliance, operational friction, and building a resilient security program. π§
Connect with our guest:
Personal LinkedIn: https://www.linkedin.com/in/madalin-bratu/
Company LinkedIn: https://www.linkedin.com/company/1-61803
Website: https://www.phi.ro
Β #CyberSecurity π #SalesStrategy πΌ #Entrepreneurship π #TheCyberWeeklyPodcast ποΈ #CareerAdvice π #B2BSales π€ #CyberSecuritySales π‘οΈ #Podcast π§
Only 40% of her company completed the annual security awareness training. Human error was the #1 risk on the register. So she stopped writing policies and started recruiting people. π₯
In this episode of The Cyber Weekly Podcast, Deo Okello sits down with Heather Reed β cybersecurity leader, Cyber Security Woman of the Year finalist, competitive cookie designer πͺ and former Cookie Wars contestant on the Food Network.
Heather came into security from marketing, people leadership and compliance, and she says that non-traditional path became her biggest advantage. She never carried the "Department of No" reputation, because she'd spent years on the other side of it.
We get into:
πΉ How she built a cybersecurity ambassador network from 5 departments to 75 ambassadors β and hit 100% training completion
πΉ Why she chose the friendliest people in the business, not the most technical
πΉ The 4 years it took to bring 23 factories and 8,000 employees into the ISMS β and how they scored their best audit ever
πΉ What a real "yes, if" conversation sounds like when the business wants speed
πΉ Tabletop exercises that actually work (hint: ask your execs what keeps them up at night)
πΉ Handling DLP and insider risk without turning security into the police π
πΉ AI agents, guardrails, and why security leaders should be talking to startups
πΉ Her honest answer to "did you ever feel you didn't belong?" β and why that question is only ever asked of women
πΉ Three things any security leader can do in the next 90 days to shift culture
β οΈ One overlooked technical issue could become a major financial, operational or reputational crisis.
But what exactly is IT risk, and why do organizations invest so much in managing it?
In this episode of The Cyber Weekly Podcast, Deo Okello sits down with IT risk and security professional Peter Muhumuza to break down IT risk in practical, easy-to-understand language.
You will learn:
π How technical weaknesses become business risks
π How organizations classify and track risks
βοΈ Which risks can be accepted and which require immediate action
π How risk professionals support innovation without becoming βMr. Noβ
π€ Why third-party and vendor risk assessments matter
βοΈ The risks created by cloud concentration and AI adoption
β
Why passing an audit does not mean risk management is complete
π How technical professionals can begin transitioning into IT risk within 90 days
Peter also explains why effective IT risk management is about more than fixing technical problems. It requires understanding business priorities, regulatory obligations, operational downtime and financial exposure.
If you work in cybersecurity, IT, banking, fintech, audit, governance or risk management, this conversation is for you.
π Like this episode
π¬ Share your biggest IT risk lesson in the comments
π Subscribe to The Cyber Weekly Podcast for more practical cybersecurity conversations
π€ Share this episode with someone interested in IT risk
#TheCyberWeekly #ITRisk #RiskManagement #Cybersecurity #InformationSecurity #GRC #ThirdPartyRisk #CloudSecurity #CyberRisk #ITGovernance
Think your company is too small for cybercriminals to care about? Think again. π¨
On this episode of The Cyber Weekly, cybersecurity leader and vCISO Brandon Krieger breaks down what businesses need to understand about cybersecurity right now.
We discuss:
π What a fractional vCISO actually does
π€ Why AI adoption needs security guardrails
π’ Why small businesses are attractive targets
π‘οΈ The cybersecurity basics companies often overlook
π Why every organization should consider a security gap assessment
π How cybersecurity professionals can work toward becoming a vCISO
πΌ Why understanding business is just as important as understanding security
Β
Follow Brandon Krieger: https://www.linkedin.com/in/brandonkrieger/
Follow KNSS Consulting Group: https://www.knssconsulting.com
Like and Follow our LinkedIn page: https://www.linkedin.com/company/thecyberweekly
Like and Follow our X page: https://twitter.com/thecyberweekly
Brandon makes an important point: cybersecurity professionals must understand the business they are protectingβnot just the technology



