Page de couverture de Defense in Depth

Defense in Depth

Defense in Depth

Auteur(s): David Spark Steve Zalewski Geoff Belknap
Écouter gratuitement

À propos de cet audio

Defense in Depth promises clear talk on cybersecurity's most controversial and confusing debates. Once a week we choose one controversial and popular cybersecurity debate and use the InfoSec community's insights to lead our discussion.2018-2024 Spark Media Solutions, LLC Politique
Épisodes
  • Are Your Security Tools Creating More Work for Your Team?
    Mar 12 2026

    All links and images can be found on CISO Series.

    Check out this post by Caleb Sima for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Evan McHenry, CISO, Robinhood.

    In this episode:

    • The information paradox
    • Setting realistic expectations
    • Prioritization over noise
    • The cart before the horse

    Huge thanks to our sponsor, Endor Labs

    Discover how AI coding agents are reshaping software supply chain risk in the State of Dependency Management. Original research from Endor Labs shows 49% of dependency versions have known vulnerabilities (and that 34% don't actually exist). Get the report to see how "shadow AI" is reshaping attack surfaces.

    Voir plus Voir moins
    36 min
  • Why Overpromising is a Dangerous Sales Tactic
    Mar 5 2026

    All links and images can be found on CISO Series.

    Check out this post, CISO, Upwind Security, for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Geoff Belknap, CISO, LinkedIn. Joining us is Octavia Howell, vp and CISO, Equifax Canada.

    In this episode:

    • Beyond the quota
    • The hard truth beats the polished bluff
    • Paying for someone else's mistakes
    • Reducing friction, increasing trust

    Huge thanks to our sponsor, ThreatLocker

    ThreatLocker takes a deny-by-default approach to endpoint security — controlling what applications can run, what can access data, and what can elevate privileges. Used by organizations that want to reduce attack surface without relying on detection alone. Learn more at threatlocker.com/ciso.

    Voir plus Voir moins
    29 min
  • Should You Phish Your Employees or Not?
    Feb 26 2026

    All links and images can be found on CISO Series.

    This week's episode is co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Mark Eggleston, CISO, CSC.

    In this episode:

    • Breaking trust to test it
    • Technical controls over testing
    • The measurement imperative
    • Fire drills, not gotchas

    Huge thanks to our sponsor, Scanner

    All your security logs end up in cloud storage like AWS S3. Scanner makes them searchable in seconds and runs real-time detections directly on that data. No pipelines, no re-ingestion. 100x faster than traditional data lakes, 10x cheaper than SIEMs. Loved by analysts. Built for AI agents. Learn more at scanner.dev.

    Voir plus Voir moins
    27 min
Pas encore de commentaire