This is Cyber Smokehouse. Join Ernie and Graeme as they grill the minds, dig into the experience, and serve up the stories of leaders in cybersecurity. Cyber Smokehouse is sponsored by TBDCyber, a cybersecurity strategy consulting firm.
All Episodes

Latest Episodes

All Episodes
#27

Building Security Programs from the Ground Up - Eddie Younker - Cyber Smokehouse - Episode #27

Take your cybersecurity program to the next level with powerful insights on structuring security reporting lines, combating shadow risk, and building an engaged, transparent team culture from scratch. It’s time to move past organizational blind spots, establish top-down AI guardrails, and align vulnerability management directly with business priorities. Who better to guide you through it than Fortune 100 security leader, former CISO at Hyundai Capital America, and former VP & CISO at LIV Golf, Eddie Younker? You will learn how reporting directly to executive leadership eliminates conflicts of interest, why effective vulnerability management relies on business support rather than just IT execution, and how to foster a "family away from family" culture that achieves industry-leading employee engagement. Get motivated to build cross-functional relationships, educate leadership teams, and take a business-first approach to security! Takeaways: The Power of Reporting Structure: Reporting directly to the CEO gives security leaders the visibility and authority needed to embed security into operational processes, whereas reporting under a CTO can create conflict between speed-to-market and risk management. Mitigating Shadow IT and AI Risks: Emerging tools and ad-hoc AI adoption create shadow risk across organizations; mitigating this requires clear corporate guardrails, top-down governance, and strong cross-departmental relationships. Business-Centric Vulnerability Management: Successfully patching high-priority vulnerabilities isn't just an IT task, it requires educating business stakeholders, managing tech debt, and securing executive buy-in to prevent operational downtime. Transparent and Inclusive Leadership: High-performing security teams are built on transparency, mutual respect, and hiring for complementary skill sets rather than redundant backgrounds. Practical Advice for Rising Security Leaders: Gaining broad experience across multiple security domains gives rising professionals the holistic perspective needed to apply security frameworks to real-world business environments. Quote of the Show "Building a security culture starts with the reporting structure... You need a structure that enables you to own security for the entire organization and drive governance that gets support from the business." - Eddie Younker\ Links: LinkedIn: https://www.linkedin.com/in/eddie-younker-19559a96/ Website: https://www.livgolf.com/ Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0  Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297  Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47  iHeart Radio: https://iheart.com/podcast/319629841/  Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#26

Protecting Delivery and Outcomes - Chris Logan - Cyber Smokehouse - Episode #26

Take your cybersecurity strategy to the next level with powerful insights on securing modern healthcare delivery, bridging the digital divide, and translating complex security tech into executive business language. It’s time to rethink patient care availability, move beyond legacy castle-and-moat models, and adopt platform-based zero trust architectures. Who better to guide you through it than U.S. Marine Corps veteran, published author, and Healthcare CISO at Zscaler, Chris Logan? You will learn how ambient AI is transforming clinical workflows, why health systems must consolidate point solutions into platform security to speed up M&A, and how servant leadership builds resilient, high-performing security teams. Get motivated to speak the language of business executives, protect critical patient care environments, and open career doors for the next generation of cyber leaders! Takeaways: Securing Care Everywhere: Healthcare has shifted from hospital-centric care to decentralized delivery across home, mobile, and wearable devices, making system availability vital to preventing negative patient outcomes. Leading with Business Outcomes Over Tech: Security leaders must frame investments in terms of clinical continuity, patient care, and revenue impact rather than technical jargon to win CFO and board support. The Rise of Ambient AI in Clinics: Ambient AI listening tools are relieving clinicians of manual EMR documentation during visits, restoring eye contact and the human relationship between doctor and patient. Platform Consolidation vs. Point Solution Noise: Health systems need platform-based security and the "80/20 rule" to reduce software sprawl, cut costs, and shorten clinic onboarding times from 18 months down to weeks. Servant Leadership & "Good Leaders Eat Last": True cyber leadership requires approachability, conducting skip-level check-ins, allowing teams room to fail forward, and opening doors for others to grow. Quote of the Show: "If you lead with technology when speaking to your board or CFO, you've already failed. They don't care about the technology, they care about the business outcome." - Chris Logan Links: LinkedIn: https://www.linkedin.com/in/logancm/ Website: https://www.zscaler.com Email: clogan@zscaler.com  christopherm.logan@gmail.com  Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0  Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297  Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47  iHeart Radio: https://iheart.com/podcast/319629841/  Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#26

Retiring from Risk - Scott Barronton - Cyber Smokehouse - Episode #26

Take your understanding of cybersecurity risk, organizational alignment, and executive career pivots to the next level with powerful insights from a 30-year industry veteran! It’s time to rethink the evolving personal liability of CISOs, how to effectively communicate cyber risk to non-technical business leaders, and what it really takes to walk away and build a successful second-act venture. Who better to guide you through it than former CISO at Finastra and Diebold Nixdorf, and co-founder and Chief Travel Officer at Sunshine Travelers Experiences, Scott Berrington? In this episode, you will learn how the rapid influx of emerging tech like AI creates mounting operational risk, the pros and cons of different CISO reporting structures, and strategies for providing true security assurance to demanding global clients. Get motivated to build empowered, self-sufficient security teams, navigate executive burnout, and turn your lifelong passions into your next big career milestone! Takeaways: The Shifting Risk-Reward Matrix for CISOs: Increasing personal and criminal liability for CISOs, coupled with 24/7/365 operational burnout, is causing many seasoned security leaders to rethink the CISO role. Emerging Tech & AI Disruption: Business leaders often adopt fast-moving technologies like AI for efficiency without fully understanding the rapid, potent risks involved, leaving CISOs to clean up structural mistakes. Optimal Security Reporting Lines: Security functions operate best when reporting to a Chief Risk Officer or Chief Legal Officer due to shared risk frameworks, whereas reporting to a CIO or CFO often introduces budget and operational friction. Proactive Customer Assurance: Rather than waiting for demanding enterprise clients to audit your environment, presenting a comprehensive, tailored security program builds deep customer trust and streamlines compliance. Delegation with Accountability: Effective leadership means giving direct reports full authority to execute while keeping a "quick hook" offline to coach them gently without destroying their internal credibility. Quote of the Show: “I was proud when I got my first CISO role, but there’s no type of pride like being an entrepreneur and taking that role of trying to build something from scratch.” - Scott Barronton Links: LinkedIn: https://www.linkedin.com/in/scottbarronton/   https://www.linkedin.com/company/sunshine-travelers-experiences/home/ Website: https://www.sunshinetravelersexperiences.com/ Podcast Link: https://podcasts.apple.com/us/podcast/sunshine-travelers-podcast/id1683937797 Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0  Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297  Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47  iHeart Radio: https://iheart.com/podcast/319629841/  Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#25

Identity, Patching, and Zero-Downtime Security - Keith Lawson - Cyber Smokehouse - Episode #25

Take your cybersecurity operations to the next level with powerful insights on managing high-volume vulnerability patches, securing healthcare IT/OT environments, and applying deep reinforcement learning to autonomous defense. It’s time to move beyond reactive security measures and build resilient, zero-downtime systems in live, life-safety environments. Who better to guide you through it than healthcare CISO, critical infrastructure veteran, and University of Michigan-Dearborn researcher, Keith Lawson? You will learn how the surge in AI coding agents is driving a "tsunami" of software patches, strategies for managing identity as the modern perimeter, and how autonomous AI agents can adapt in real time to protect critical infrastructure. Get motivated to foster a zero-blame, collaborative culture that empowers your technical and non-technical teams to solve complex security challenges together. Takeaways: The Vulnerability Tsunami: The adoption of AI coding agents by software vendors is generating a massive wave of bug fixes and corresponding exploits, requiring organizations to automate testing and speed up patching cycles. Identity as the Modern Perimeter: As healthcare and enterprise data shift to cloud and SaaS environments, human vulnerabilities and weak identity controls, rather than traditional network perimeters, have become the primary target for social engineering and exploitation. Zero-Downtime Patching in Healthcare: Securing complex hospital networks (spanning medical IoT, legacy software, and life-critical devices) requires strict pre-planning, automated testing, and a zero-tolerance approach for service disruptions. Applied Reinforcement Learning: Unlike static large language models (LLMs), reinforcement learning enables real-time, continuous online learning for autonomous cyber defense against zero-day threats. Fostering a Zero-Blame Culture: Effective security leadership relies on open collaboration, empowering staff across all departments, and maintaining a transparent, zero-blame environment so teams can report mistakes and fix root causes fast. Quote of the Show: "In security, I think open honesty and sharing is the best thing that we can do... To me, security is a team sport." - Keith Lawson Links: LinkedIn: https://www.linkedin.com/in/j-keith-lawson/ Website: blog.9600baud.net http://www.lhsc.on.ca Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0  Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297  Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47  iHeart Radio: https://iheart.com/podcast/319629841/  Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#24

Humans Still Win at Security - Shannon Garcia - Cyber Smokehouse - Episode #24

Get ready to challenge everything you assume about AI's role in cybersecurity. Shannon Garcia, founder of Strategic Defense and a veteran red team leader with stops at Trustwave, SecureWorks, IBM, and Kudelski Security, joins the Cyber Smokehouse to break down why manual, human-led penetration testing still outperforms automated AI tools, and why that might not last forever. You'll learn how shadow IT quietly drains company budgets, why remote work has changed both testing methodology and phishing success rates, and how translating technical findings into business language can protect million-dollar contracts. Plus, Shannon shares her unlikely path from 11 years as an AMD engineer to building two cybersecurity companies from scratch. Takeaways: AI is reshaping conversations across cybersecurity, but Shannon's teams still rely on manual, human-led penetration testing. She notes that automated AI pen testing platforms can't yet handle certain test types, like wireless assessments, and that clients often value the real-time communication a human tester provides over an automated tool. Shadow IT remains a persistent and growing risk, not just from a security standpoint but from a business one. Shannon points out that when business units are given autonomy to buy and deploy their own tools, companies can end up bleeding money on redundant or unnecessary licensing without realizing it. Remote work has changed both how testing gets done and how social engineering performs. Without a traditional office network to test, engagements now lean heavily on VPN and SaaS-based access reviews, and Shannon has found that phishing and vishing success rates drop significantly when employees work from home and simply don't answer the phone. Shannon describes her leadership style as people-first and curiosity-driven. She asks her team detailed questions not to micromanage, but to genuinely understand their thought process and challenges, which she says helps her advocate for them with clients. Translating technical findings for non-technical executives has been one of Shannon's most valuable skills. She frames security findings in terms of business risk and cost avoidance rather than pure ROI, which has directly helped clients unblock stalled contracts tied to security requirements. Shannon transitioned into cybersecurity after being laid off from an 11-year engineering career at AMD in 2012. Her advice to newcomers is to recognize the transferable soft skills they already have, since communication and reliability matter as much as technical ability when building a career in the field. Looking ahead, Shannon is considering a potential acquisition to expand her pen testing company's capabilities, while continuing to grow her AppSec-focused company's response to AI-driven risk in the software development lifecycle. She also has a long-planned mentorship program for aspiring cybersecurity practice leads still in development. Quote of the Show: “The thing that I love the most about running my own business is I don't have to ask for permission.” - Shannon Garcia Links: LinkedIn: https://www.linkedin.com/in/shannongarcia/ Website: strategicdefense.co Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0  Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297  Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47  iHeart Radio: https://iheart.com/podcast/319629841/  Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550