Rephonic
Artwork for CISO Stories Podcast

CISO Stories Podcast (Video)

SC Media
Cybersecurity
Cloud Security
Artificial Intelligence
Incident Response
Data Governance
Emerging Technologies
GDPR
Digital Transformation
Information Security
Tool Selection
Identity Management
Cisos
Venture Capital
Tool Rationalization
Vulnerability Management
Data Privacy
Cyber Liability Insurance
Small and Medium Businesses
CISO
GRC (governance, Risk, Compliance)

SC Media and Horizon3.ai are proud to present this month's CISO Stories program, where CISOs share tales from the trenches and unpack leadership lessons learned along the way. Hosted by Jessica Hoffman.

PublishesMonthlyEpisodes87Founded3 years ago
Number of ListenersCategories
TechnologyBusiness

Listen to this Podcast

Artwork for CISO Stories Podcast

Latest Episodes

In this episode of CISO Stories, Jessica Hoffman sits down with Matt Lee to explore attack surface management, AWS security, and the cloud misconfigurations that can put organizations at risk.

Matt shares lessons from his experience auditing cloud ... more

AI is changing cloud security fast, but the biggest challenge is not just adoption. It is governance. In this episode, Jess sits down with Brent Neil, CISO at RapidScale, to talk about what CISOs should be watching as AI becomes embedded in cloud env... more

In this episode, former FBI cyber leader Jason Manar joins us to unpack the state of critical infrastructure security and why small and medium-sized businesses are more connected to it than they realize. From power, telecom, healthcare, finance, and ... more

Identity and access management is often sold as a technical problem, but real-world deployments tell a different story. For MSSPs managing access across multiple client environments, IAM becomes a test of trust, accountability, decision fatigue, and ... more

Jess talks with Rich about what it takes to secure a cloud-first organization at scale. Rich explains how compliance as code helps teams build secure-by-default environments in AWS and Azure. He also shares why continuous monitoring gives organizatio... more

Threat intelligence too often arrives as a steady stream of alerts that don't translate into clear, timely decisions. This episode explores how public-sector intel flows today through channels like CISA, MS-ISAC, and CIS—and why changes in funding an... more

CISO Jadee Hanson shares how Vanta "drinks its own champagne," running on NIST CSF with quarterly baseline reviews and using Vanta's GRC platform to turn every release into live UAT for privacy, governance, and compliance. We rethink third-party mana... more

Title: Keys Without People" — John Heasman on Cleaning Up Non-Human Access

Summary: John breaks today's non-human identity mess into three buckets: core tools your business runs on, old/one-off integrations that linger, and engineer tokens left beh... more

Key Facts

Accepts Guests
Accepts Sponsors
Contact Information
Podcast Host
Number of Listeners
Find out how many people listen to this podcast per episode and each month.

Similar Podcasts

People also subscribe to these shows.

Recent Guests

Matt Lee
Author of Core Zero to Hero at AWS Security, an animated guide to security in the cloud
Independent security expert
Episode: Attack Surface Management - Matt Lea - CSP #227
Brent Neal
Chief Information Security Officer at RapidScale
RapidScale
Episode: Cloud Security Meets AI: What CISOs Need to Govern Before They Scale - Brent Neal - CSP #226
Jason Manar
Former FBI cyber operations official, now with Cassera/CISO
CISO / Cassera
Episode: Critical Infrastructure: The Risk Hiding in Plain Sight - Jason Manar - CSP #225
Dustin Sacks
Dr. of Computer Science; cybersecurity practitioner with 20+ years of experience; former deputy CISO for Governance Risk and Compliance at a large fuel services company
Behavioral Insights in Cybersecurity author; Speaker
Episode: IAM for MSSPs: The Hidden Risk of Blind Trust - Dustin Sachs - CSP #224
Richard Marcus
Chief Information Security Officer at Optro (formerly Audit Board)
Optro
Episode: From Compliance to Code: Rethinking Cloud Security - Richard Marcus - CSP #223
Ian Washburn
Deputy CISO for the University of Notre Dame
University of Notre Dame
Episode: From Alerts to Action: Making Public–Private Threat Intel Actually Useful - Ian Washburn - CSP #222
Jadee Hanson
CISO, Vanta (GRC company)
Vanta
Episode: Beyond Vendor Risk: Real-Time GRC, AI, and Protecting App User Data - Jadee Hanson - CSP #221
John Heasman
Security leader discussing NHIs and IAM best practices
Proof Is Today
Episode: Keys Without People — John Heasman on Cleaning Up Non-Human Access - John Heasman - CSP #220
Rakesh Soni
Founder and CEO, LoginRadius
LoginRadius
Episode: Agents at the Door: Vetting Non-Human Identities in External IAM - Rakesh Soni - CSP #219

Host

Jessica Hoffman
Host of CISO Stories Podcast

Top Technology Podcasts

Tomorrow, Today
Tomorrow, TodayShekhar Natarajan
The Room Podcast
The Room PodcastClaudia Laurie and Madison McIlwain
Acquired
AcquiredBen Gilbert and David Rosenthal
Eye On A.I.
Eye On A.I.Craig S. Smith
Building AI Boston
Building AI BostonBuilding AI Boston
Hard Fork
Hard ForkThe New York Times
Bourbon with Brad
Bourbon with BradCompletely Offensively LLC

Talking Points

Recent interactions between the hosts and their guests.

Attack Surface Management - Matt Lea - CSP #227
Q: What are the top recurring findings you see in AWS environments that teams should address first?
Common patterns include misconfigured security groups that expose services to the world, S3 buckets left publicly accessible, liberal IAM permissions or wildcard access, and weak data protection practices like uncycled credentials. Prioritizing network visibility, strict IAM controls, and ensuring proper data exposure policies materially reduce risk.
Attack Surface Management - Matt Lea - CSP #227
Q: What is Attack Surface Management really about, and how should executives think about it in practice?
ASM is about understanding and controlling every point of exposure across cloud environments, especially around human access, data exposure, and network configurations. Executives should focus on governance, implemented least-privilege access, and layered defenses like network mapping, IAM discipline, and WAFs to reduce risk rather than relying on magic bullets.
OT on the Frontlines: Threat Intelligence You Can't Ignore - Dawn Cappelli - CSP #216
Q: How has the threat landscape shifted for OT in the last few years, and what should CISOs prioritize?
Threat actors beyond traditional nation-states and hacktivists are increasingly targeting OT, with a focus on operational data and process control information. CISOs should prioritize IT-OT segmentation, OT-specific visibility and monitoring, and cross-sector collaboration to share threat intelligence and defenses.
OT on the Frontlines: Threat Intelligence You Can't Ignore - Dawn Cappelli - CSP #216
Q: What practical steps can organizations take now to prepare for Pipe Dream and similar threats?
Join OT CERT for free resources, follow the SANS Five Critical Controls for ICS, establish an OT incident response plan with tabletop exercises, secure remote access with MFA, implement defensible OT architecture with tailored monitoring, and adopt risk-based vulnerability management that prioritizes now/next/never vulnerabilities.
OT on the Frontlines: Threat Intelligence You Can't Ignore - Dawn Cappelli - CSP #216
Q: What is Pipe Dream and why is it a game changer for OT security?
Pipe Dream is a highly sophisticated ICS malware that affects multiple ICS protocols across vendors, making traditional patching ineffective. Defenders must implement a comprehensive OT cybersecurity program, including strong network segmentation, monitoring, and incident response practices; there is no single device fix, so a holistic approach is required.

Audience Metrics

Listeners, social reach, demographics and more for this podcast.

Listeners per Episode
Gender Skew
Location
Interests
Professions
Age Range
Household Income
Social Media Reach

Frequently Asked Questions About CISO Stories Podcast

What is CISO Stories Podcast about and what kind of topics does it cover?

Focusing on the experiences and insights of Chief Information Security Officers (CISOs), the content revolves around critical issues in cybersecurity, data privacy, and risk management. Episodes frequently feature conversations with industry leaders, encompassing topics such as attack surface management, incident response, and the evolving landscape of cyber liability insurance. The discussions are not only technical but also delve into leadership lessons and the human elements of cybersecurity, including the necessity of employee training and understanding organizational vulnerabilities. This unique blend of storytelling and expert advice aims to educate and inform professionals navigating the complex world of information security.

Where can I find podcast stats for CISO Stories Podcast?

Rephonic provides a wide range of podcast stats for CISO Stories Podcast. We scanned the web and collated all of the information that we could find in our comprehensive podcast database. See how many people listen to CISO Stories Podcast and access YouTube viewership numbers, download stats, audience demographics, chart rankings, ratings, reviews and more.

How many listeners does CISO Stories Podcast get?

Rephonic provides a full set of podcast information for four million podcasts, including the number of listeners. View further listenership figures for CISO Stories Podcast, including podcast download numbers and subscriber numbers, so you can make better decisions about which podcasts to sponsor or be a guest on. You will need to upgrade your account to access this premium data.

What are the audience demographics for CISO Stories Podcast?

Rephonic provides comprehensive predictive audience data for CISO Stories Podcast, including gender skew, age, country, political leaning, income, professions, education level, and interests. You can access these listener demographics by upgrading your account.

How many subscribers and views does CISO Stories Podcast have?

To see how many followers or subscribers CISO Stories Podcast has on Spotify and other platforms such as Castbox and Podcast Addict, simply upgrade your account. You'll also find viewership figures for their YouTube channel if they have one.

Which podcasts are similar to CISO Stories Podcast?

These podcasts share a similar audience with CISO Stories Podcast:

1. Cybersecurity Headlines

How many episodes of CISO Stories Podcast are there?

CISO Stories Podcast launched 3 years ago and published 87 episodes to date. You can find more information about this podcast including rankings, audience demographics and engagement in our podcast database.

How do I contact CISO Stories Podcast?

Our systems regularly scour the web to find email addresses and social media links for this podcast. We scanned the web and collated all of the contact information that we could find in our podcast database. But in the unlikely event that you can't find what you're looking for, our concierge service lets you request our research team to source better contacts for you.

Where can I see ratings and reviews for CISO Stories Podcast?

Rephonic pulls ratings and reviews for CISO Stories Podcast from multiple sources, including Spotify, Apple Podcasts, Castbox, and Podcast Addict.

View all the reviews in one place instead of visiting each platform individually and use this information to decide if a show is worth pitching or not.

How do I access podcast episode transcripts for CISO Stories Podcast?

Rephonic provides full transcripts for episodes of CISO Stories Podcast. Search within each transcript for your keywords, whether they be topics, brands or people, and figure out if it's worth pitching as a guest or sponsor. You can even set-up alerts to get notified when your keywords are mentioned.

What guests have appeared on CISO Stories Podcast?

Recent guests on CISO Stories Podcast include:

1. Matt Lee
2. Brent Neal
3. Jason Manar
4. Dustin Sacks
5. Richard Marcus
6. Ian Washburn
7. Jadee Hanson
8. John Heasman

To view more recent guests and their details, simply upgrade your Rephonic account. You'll also get access to a typical guest profile to help you decide if the show is worth pitching.

Find and pitch the right podcasts

We help savvy brands, marketers and PR professionals to find the right podcasts for any topic or niche. Get the data and contacts you need to pitch podcasts at scale and turn listeners into customers.
Try it free for 7 days