OFFRE D'UNE DURÉE LIMITÉE | Obtenez 3 mois à 0.99 $ par mois

14.95 $/mois par la suite. Des conditions s'appliquent.
Page de couverture de The Art of Cybersecurity: Real-World Risk & Compliance Strategies

The Art of Cybersecurity: Real-World Risk & Compliance Strategies

The Art of Cybersecurity: Real-World Risk & Compliance Strategies

Auteur(s): Cheri Hotman
Écouter gratuitement

À propos de cet audio

Cybersecurity is as much art as it is science or technology. It must be creatively designed, right-sized, implemented, and sustained—all within stealthy constraints: finite time, budget, resources. Meanwhile, customers demand this framework, that standard, and yet another security questionnaire. It’s a lot to juggle—balancing security that genuinely protects people and data with the theater that often slips into meaningless checkbox exercises. On this podcast, expect sharp, unfiltered conversations about the realities of cyber and what it truly takes to do it right—and make it actually matter.Cheri Hotman
Épisodes
  • Continuous Improvement in Cyber: Findings Are the Point
    Jan 2 2026

    In this episode, Cheri Hotman sits down with long-time colleague and GRC leader Peter Spier for a candid, no-nonsense conversation about what actually keeps organizations secure and what quietly puts them at risk.

    Peter brings more than two decades of experience across PCI, audits, and enterprise risk to unpack a topic most teams avoid. Integrity in GRC. Together, they challenge the obsession with green checkmarks, clean audit reports, and “passing” frameworks while ignoring what really matters. Reducing real risk.

    This conversation cuts straight through common myths:

    • Why a report with zero findings should make you nervous, not confident

    • How audits differ fundamentally from running a security program

    • The danger of scoping games and checkbox compliance

    • Why continuous improvement requires uncomfortable conversations

    • How ego, incentives, and fear quietly undermine security decisions

    Cheri and Peter also explore the human side of cybersecurity. Coachability, transparency, and the willingness to surface problems early before attackers do. This episode is for leaders, practitioners, and auditors who care less about appearances and more about building programs that actually protect the business.

    If you have ever felt uneasy about a “perfect” audit, struggled to push bad news up the chain, or wondered whether your compliance program is giving you a false sense of security, this conversation will resonate.

    Voir plus Voir moins
    57 min
  • From CPA to Cyber Leader: Seeing the Whole Business
    Dec 12 2025

    In this episode, Cheri Hotman sits down with Joe Kodali, a fellow CPA turned cybersecurity and GRC leader, to have a blunt, practitioner-level conversation about what is actually broken in modern cybersecurity programs and why compliance theater is making organizations less secure, not more.

    They unpack the unique value CPAs bring to cybersecurity, not because of accounting, but because of how auditors are trained to understand entire businesses, ask uncomfortable questions, and tie controls back to real risk and return on investment. From there, the discussion goes deep into the widening gap between executives and cyber teams, the failure of checkbox audits, and how GRC tools and low-quality SOC 2 practices have created a dangerous false sense of security.

    Cheri and Joe challenge the industry’s obsession with compliance over governance and risk, calling out poor scoping, copy-paste controls, and the misuse of frameworks that were never meant to be treated as templates. They also address the hard truth that tools do not fix broken programs, people and discipline do.

    The conversation closes with a candid discussion on why governance is the most overlooked and undervalued part of GRC, how boards should be asking better questions, and what it actually takes to build a cyber program that protects the business rather than just passing audits.

    This episode is required listening for CISOs, security leaders, GRC practitioners, auditors, and executives who want real security outcomes instead of green checkmarks.

    Voir plus Voir moins
    55 min
  • Inside CMMC: The Real Challenges, the Real Stakes, and the Real Work
    Dec 11 2025

    In this episode, Cheri Hotman sits down with CMMC expert and strategist Linda Rust for a direct, unscripted conversation about what CMMC really means for defense contractors, why so many organizations get it wrong, and how leaders can approach compliance with clarity instead of chaos.

    Linda brings more than 25 years of engineering and mission-critical technology leadership to the table. She breaks down why CMMC is fundamentally a business issue rather than an IT project, why third-party accountability is often the only thing that finally moves organizations to action, and why “cheap” approaches end up being the most expensive mistakes companies make.

    Cheri and Linda dig into:
    • What CMMC is (and isn’t)
    • Why scoping and understanding your data matters more than any technical control
    • Why leadership, not IT, must own the strategy
    • The real cost drivers behind CMMC and why labor—not tools—is the biggest factor
    • How small companies get themselves into false-claims trouble without realizing it
    • What’s coming next with FAR CUI and NIST 800-171 Revision 3
    • How organizations can right-size their efforts instead of chasing shortcuts

    If you want a frank, practical explanation of CMMC from two people who have lived it for years, this episode will help you understand the landscape, avoid costly pitfalls, and build a program that leaders can actually sustain.

    Voir plus Voir moins
    49 min
Pas encore de commentaire