This is Cyber Smokehouse. Join Ernie and Graeme as they grill the minds, dig into the experience, and serve up the stories of leaders in cybersecurity. Cyber Smokehouse is sponsored by TBDCyber, a cybersecurity strategy consulting firm.
All Episodes

Latest Episodes

All Episodes
#24

Humans Still Win at Security - Shannon Garcia - Cyber Smokehouse - Episode #24

Get ready to challenge everything you assume about AI's role in cybersecurity. Shannon Garcia, founder of Strategic Defense and a veteran red team leader with stops at Trustwave, SecureWorks, IBM, and Kudelski Security, joins the Cyber Smokehouse to break down why manual, human-led penetration testing still outperforms automated AI tools, and why that might not last forever. You'll learn how shadow IT quietly drains company budgets, why remote work has changed both testing methodology and phishing success rates, and how translating technical findings into business language can protect million-dollar contracts. Plus, Shannon shares her unlikely path from 11 years as an AMD engineer to building two cybersecurity companies from scratch. Takeaways: AI is reshaping conversations across cybersecurity, but Shannon's teams still rely on manual, human-led penetration testing. She notes that automated AI pen testing platforms can't yet handle certain test types, like wireless assessments, and that clients often value the real-time communication a human tester provides over an automated tool.Shadow IT remains a persistent and growing risk, not just from a security standpoint but from a business one. Shannon points out that when business units are given autonomy to buy and deploy their own tools, companies can end up bleeding money on redundant or unnecessary licensing without realizing it.Remote work has changed both how testing gets done and how social engineering performs. Without a traditional office network to test, engagements now lean heavily on VPN and SaaS-based access reviews, and Shannon has found that phishing and vishing success rates drop significantly when employees work from home and simply don't answer the phone.Shannon describes her leadership style as people-first and curiosity-driven. She asks her team detailed questions not to micromanage, but to genuinely understand their thought process and challenges, which she says helps her advocate for them with clients.Translating technical findings for non-technical executives has been one of Shannon's most valuable skills. She frames security findings in terms of business risk and cost avoidance rather than pure ROI, which has directly helped clients unblock stalled contracts tied to security requirements.Shannon transitioned into cybersecurity after being laid off from an 11-year engineering career at AMD in 2012. Her advice to newcomers is to recognize the transferable soft skills they already have, since communication and reliability matter as much as technical ability when building a career in the field.Looking ahead, Shannon is considering a potential acquisition to expand her pen testing company's capabilities, while continuing to grow her AppSec-focused company's response to AI-driven risk in the software development lifecycle. She also has a long-planned mentorship program for aspiring cybersecurity practice leads still in development. Quote of the Show:“The thing that I love the most about running my own business is I don't have to ask for permission.” - Shannon Garcia Links:LinkedIn: https://www.linkedin.com/in/shannongarcia/Website: strategicdefense.co Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#23

Building Better Security Leaders - Ward Balcerzak - Cyber Smokehouse - Episode #23

Strong cybersecurity programs aren't built through quick fixes, they're built through thoughtful leadership, patient execution, and investing in people. In this episode of Cyber Smokehouse, Ernie Anderson and Graeme Payne sit down with Ward Balcerzak, Field CISO at Sentra, to discuss what effective security leadership looks like in today's rapidly evolving landscape. Ward shares lessons from building security programs, mentoring future leaders, adopting AI responsibly, and helping organizations avoid reactive decision-making. From creating realistic AI roadmaps to developing cybersecurity talent and leading through change, this conversation offers practical guidance for security leaders focused on building resilient organizations for the long term. Takeaways:Successful AI adoption requires thoughtful planning rather than rushed implementation. Ward explains that many organizations are reacting to AI with unrealistic timelines and expectations. Leaders should slow down, identify their objectives, understand their gaps, and build a roadmap instead of treating AI as an overnight transformation. Effective security leaders know when to slow momentum without stopping progress. Rather than simply saying "no" to new initiatives, Ward advocates helping the business move forward responsibly by balancing innovation with practical execution and demonstrating measurable progress along the way. AI should eliminate repetitive work, not cybersecurity careers. Ward predicts entry-level analyst responsibilities will become increasingly automated, allowing security professionals to develop higher-value technical and strategic skills instead of spending time on repetitive manual tasks. Cybersecurity professionals should proactively develop new skills as technology evolves. Rather than fearing AI, Ward encourages practitioners to seek additional projects, expand their expertise, and have ongoing career conversations with leadership to remain valuable contributors. Networking has become one of the most valuable career investments in cybersecurity. Technical knowledge alone is no longer enough. Building relationships, participating in industry events, and maintaining an active professional network create opportunities that certifications alone often cannot provide. Leadership requires making difficult decisions with empathy. Ward reflects on both hiring and performance management, acknowledging that leaders often want to help people personally while still making decisions that are best for the organization. Quote of the Show:“Take a breath, zoom out, figure out what you're actually trying to accomplish.” -  Ward Balcerzak Links: LinkedIn: https://www.linkedin.com/in/ward-balcerzak/Website: https://www.sentra.io/ Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#22

Predictive Cyber Risk - Tim and Suzanne O’Neil - Cyber Smokehouse - Episode #22

Most security programs are built around understanding what has already happened, but what if organizations could begin anticipating cyber threats before they materialize? In this episode of Cyber Smokehouse, Ernie Anderson and Graeme Payne welcome Tim and Suzanne O'Neil, founders of AigisPoint Predictive Intelligence. Drawing on decades of experience spanning enterprise security architecture, military leadership, entrepreneurship, and business strategy, they discuss their approach to predictive cyber risk, how AI and machine learning are reshaping threat modeling, and the realities of building an innovative cybersecurity startup. From balancing innovation with security to understanding AI's limitations, this conversation explores how organizations can begin thinking beyond reactive cybersecurity while remaining grounded in practical risk management.  Takeaways:Traditional threat modeling remains largely static, creating an opportunity to apply AI and machine learning to forecast potential cyber threats before they emerge rather than relying solely on historical attack data. Publicly available sources, including industry reports, breach investigations, and threat intelligence, contain valuable information that can be combined with modern analytical techniques to identify emerging trends instead of simply documenting the past. Building innovative cybersecurity products requires leaders to constantly balance investment decisions, innovation, and acceptable business risk, recognizing that organizations cannot fund every initiative simultaneously. Early-stage cybersecurity companies face the challenge of proving value through customer adoption while simultaneously developing secure, production-ready platforms and meeting investor expectations. AI should be viewed as an enabling technology, not an infallible decision-maker. Human oversight remains essential because AI systems can still produce flawed outcomes and require validation before being trusted in security-critical environments. As AI automates more routine security analysis, cybersecurity roles will continue to evolve rather than disappear, creating demand for new specialties as adversaries increasingly leverage AI-driven techniques. Entrepreneurship in cybersecurity requires technical expertise alongside resilience, adaptability, and a willingness to navigate uncertainty while transforming innovative ideas into commercially viable products. Quote of the Show:“Currently everybody's looking backwards.” - Suzanne O’Neil Links:LinkedIn: https://www.linkedin.com/in/suzanne-oneil-7490643b8/  linkedin.com/in/tim-o-22774918/?skipRedirect=true Website: https://www.aigispoint.net/ Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#21

Managing Risk at Scale - John Rogers - Cyber Smokehouse - Episode #21

Cybersecurity leaders today face a challenge that extends far beyond technology: keeping pace with constant change. In this episode of Cyber Smokehouse, Ernie Anderson and Graeme Payne sit down with John Rogers, Chief Information Security Officer and Head of Technology Risk at MSCI. Drawing on experience spanning consulting, financial services, and executive security leadership, John shares his perspective on AI governance, third-party risk management, board communication, and the growing complexity facing security teams. Listeners will gain practical insights into how organizations can approach AI governance, communicate cyber risk effectively to executives and boards, rethink traditional third-party risk practices, and prepare for a future where security leaders must balance innovation with increasingly complex threats.  Takeaways:The speed of change remains one of the biggest challenges facing security leaders today, with AI accelerating both innovation and the barrier to entry for attackers. AI governance starts with visibility. Before organizations can govern AI effectively, they need an inventory of where AI systems and agents actually exist across the business. Citizen development creates opportunities for innovation but also introduces new security responsibilities that many non-technical users may not fully understand. Effective board communication requires focusing on risk, change, and business impact rather than diving into highly technical details that executives may not find actionable. Traditional third-party risk management approaches often rely heavily on questionnaires that may not provide meaningful security insight, highlighting the need for more risk-focused evaluation methods. Security teams are continually playing catch-up as new technologies emerge, while foundational controls such as encryption and access management remain consistently important. Cybersecurity professionals entering the field should embrace AI tools rather than fear them, as familiarity with AI is rapidly becoming a critical skill regardless of technical background. Quote of the Show:“It's impossible to be an expert at everything.” - John Rogers Links: LinkedIn: https://www.linkedin.com/in/johnsrogers/Website: http://www.msci.com Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#19

Foundation First - Michael Myint - Cyber Smokehouse - Episode #19

Most cybersecurity conversations start with technology. Michael Myint starts with the foundation. In this episode of Cyber Smokehouse, Ernie Anderson and Graeme Payne sit down with Michael Myint, a cybersecurity executive whose thirty year career spans Big Four consulting, global enterprises, and high growth healthcare startups. He has built programs from scratch, led organizations through public incidents, and mentored security leaders who have gone on to surpass him. You will walk away with a sharper view of where AI is genuinely changing the threat landscape, why vendor consolidation is coming, whether organizations are ready or not, and what separates the security professionals who rise from the ones who stall. Takeaways:Board communication lives or dies on business relevance. Phishing rates and patch counts belong in the appendix. Metrics tied to revenue, speed to delivery, and product outcomes are what earn executive attention and budget support.AI is disrupting the entry level pipeline in ways the industry has not fully reckoned with. New practitioners who rely on prompt engineering without foundational knowledge will struggle when things break and nobody knows why.Vendor consolidation is coming. The era of niche tools for every sliver of the security stack is giving way to platforms that cover more ground at lower cost, and leaders who get ahead of that shift will be better positioned.Quantum computing combined with AI capabilities is a legitimate long term concern. Nation state actors are already better resourced than most enterprises, and that gap only widens as quantum matures.The CISO is not the department of no. Security leaders who lean on restriction and compliance theater lose credibility quickly. The ones who earn trust show up with solutions and speak the language of the business.Building future leaders requires giving real ownership, not just tasks. Cross training across security functions and evaluating people on program outcomes rather than activity is what develops professionals who can eventually lead on their own.A foundational background still matters before moving into a cybersecurity role. Understanding networking, identity, and how systems actually work provides context that no certification shortcut can replace.Quote of the Show:“"Be curious, dig a lot, be a go-getter, be a problem solver, take ownership."- Michael MyintLinks:LinkedIn: https://www.linkedin.com/in/michaelmyint/Website: https://adapthealth.com/ Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550