All Episodes

Displaying 1 - 20 of 24 in total

#24

Humans Still Win at Security - Shannon Garcia - Cyber Smokehouse - Episode #24

Get ready to challenge everything you assume about AI's role in cybersecurity. Shannon Garcia, founder of Strategic Defense and a veteran red team leader with stops at Trustwave, SecureWorks, IBM, and Kudelski Security, joins the Cyber Smokehouse to break down why manual, human-led penetration testing still outperforms automated AI tools, and why that might not last forever. You'll learn how shadow IT quietly drains company budgets, why remote work has changed both testing methodology and phishing success rates, and how translating technical findings into business language can protect million-dollar contracts. Plus, Shannon shares her unlikely path from 11 years as an AMD engineer to building two cybersecurity companies from scratch. Takeaways: AI is reshaping conversations across cybersecurity, but Shannon's teams still rely on manual, human-led penetration testing. She notes that automated AI pen testing platforms can't yet handle certain test types, like wireless assessments, and that clients often value the real-time communication a human tester provides over an automated tool.Shadow IT remains a persistent and growing risk, not just from a security standpoint but from a business one. Shannon points out that when business units are given autonomy to buy and deploy their own tools, companies can end up bleeding money on redundant or unnecessary licensing without realizing it.Remote work has changed both how testing gets done and how social engineering performs. Without a traditional office network to test, engagements now lean heavily on VPN and SaaS-based access reviews, and Shannon has found that phishing and vishing success rates drop significantly when employees work from home and simply don't answer the phone.Shannon describes her leadership style as people-first and curiosity-driven. She asks her team detailed questions not to micromanage, but to genuinely understand their thought process and challenges, which she says helps her advocate for them with clients.Translating technical findings for non-technical executives has been one of Shannon's most valuable skills. She frames security findings in terms of business risk and cost avoidance rather than pure ROI, which has directly helped clients unblock stalled contracts tied to security requirements.Shannon transitioned into cybersecurity after being laid off from an 11-year engineering career at AMD in 2012. Her advice to newcomers is to recognize the transferable soft skills they already have, since communication and reliability matter as much as technical ability when building a career in the field.Looking ahead, Shannon is considering a potential acquisition to expand her pen testing company's capabilities, while continuing to grow her AppSec-focused company's response to AI-driven risk in the software development lifecycle. She also has a long-planned mentorship program for aspiring cybersecurity practice leads still in development. Quote of the Show:“The thing that I love the most about running my own business is I don't have to ask for permission.” - Shannon Garcia Links:LinkedIn: https://www.linkedin.com/in/shannongarcia/Website: strategicdefense.co Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#23

Building Better Security Leaders - Ward Balcerzak - Cyber Smokehouse - Episode #23

Strong cybersecurity programs aren't built through quick fixes, they're built through thoughtful leadership, patient execution, and investing in people. In this episode of Cyber Smokehouse, Ernie Anderson and Graeme Payne sit down with Ward Balcerzak, Field CISO at Sentra, to discuss what effective security leadership looks like in today's rapidly evolving landscape. Ward shares lessons from building security programs, mentoring future leaders, adopting AI responsibly, and helping organizations avoid reactive decision-making. From creating realistic AI roadmaps to developing cybersecurity talent and leading through change, this conversation offers practical guidance for security leaders focused on building resilient organizations for the long term. Takeaways:Successful AI adoption requires thoughtful planning rather than rushed implementation. Ward explains that many organizations are reacting to AI with unrealistic timelines and expectations. Leaders should slow down, identify their objectives, understand their gaps, and build a roadmap instead of treating AI as an overnight transformation. Effective security leaders know when to slow momentum without stopping progress. Rather than simply saying "no" to new initiatives, Ward advocates helping the business move forward responsibly by balancing innovation with practical execution and demonstrating measurable progress along the way. AI should eliminate repetitive work, not cybersecurity careers. Ward predicts entry-level analyst responsibilities will become increasingly automated, allowing security professionals to develop higher-value technical and strategic skills instead of spending time on repetitive manual tasks. Cybersecurity professionals should proactively develop new skills as technology evolves. Rather than fearing AI, Ward encourages practitioners to seek additional projects, expand their expertise, and have ongoing career conversations with leadership to remain valuable contributors. Networking has become one of the most valuable career investments in cybersecurity. Technical knowledge alone is no longer enough. Building relationships, participating in industry events, and maintaining an active professional network create opportunities that certifications alone often cannot provide. Leadership requires making difficult decisions with empathy. Ward reflects on both hiring and performance management, acknowledging that leaders often want to help people personally while still making decisions that are best for the organization. Quote of the Show:“Take a breath, zoom out, figure out what you're actually trying to accomplish.” -  Ward Balcerzak Links: LinkedIn: https://www.linkedin.com/in/ward-balcerzak/Website: https://www.sentra.io/ Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#22

Predictive Cyber Risk - Tim and Suzanne O’Neil - Cyber Smokehouse - Episode #22

Most security programs are built around understanding what has already happened, but what if organizations could begin anticipating cyber threats before they materialize? In this episode of Cyber Smokehouse, Ernie Anderson and Graeme Payne welcome Tim and Suzanne O'Neil, founders of AigisPoint Predictive Intelligence. Drawing on decades of experience spanning enterprise security architecture, military leadership, entrepreneurship, and business strategy, they discuss their approach to predictive cyber risk, how AI and machine learning are reshaping threat modeling, and the realities of building an innovative cybersecurity startup. From balancing innovation with security to understanding AI's limitations, this conversation explores how organizations can begin thinking beyond reactive cybersecurity while remaining grounded in practical risk management.  Takeaways:Traditional threat modeling remains largely static, creating an opportunity to apply AI and machine learning to forecast potential cyber threats before they emerge rather than relying solely on historical attack data. Publicly available sources, including industry reports, breach investigations, and threat intelligence, contain valuable information that can be combined with modern analytical techniques to identify emerging trends instead of simply documenting the past. Building innovative cybersecurity products requires leaders to constantly balance investment decisions, innovation, and acceptable business risk, recognizing that organizations cannot fund every initiative simultaneously. Early-stage cybersecurity companies face the challenge of proving value through customer adoption while simultaneously developing secure, production-ready platforms and meeting investor expectations. AI should be viewed as an enabling technology, not an infallible decision-maker. Human oversight remains essential because AI systems can still produce flawed outcomes and require validation before being trusted in security-critical environments. As AI automates more routine security analysis, cybersecurity roles will continue to evolve rather than disappear, creating demand for new specialties as adversaries increasingly leverage AI-driven techniques. Entrepreneurship in cybersecurity requires technical expertise alongside resilience, adaptability, and a willingness to navigate uncertainty while transforming innovative ideas into commercially viable products. Quote of the Show:“Currently everybody's looking backwards.” - Suzanne O’Neil Links:LinkedIn: https://www.linkedin.com/in/suzanne-oneil-7490643b8/  linkedin.com/in/tim-o-22774918/?skipRedirect=true Website: https://www.aigispoint.net/ Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#21

Managing Risk at Scale - John Rogers - Cyber Smokehouse - Episode #21

Cybersecurity leaders today face a challenge that extends far beyond technology: keeping pace with constant change. In this episode of Cyber Smokehouse, Ernie Anderson and Graeme Payne sit down with John Rogers, Chief Information Security Officer and Head of Technology Risk at MSCI. Drawing on experience spanning consulting, financial services, and executive security leadership, John shares his perspective on AI governance, third-party risk management, board communication, and the growing complexity facing security teams. Listeners will gain practical insights into how organizations can approach AI governance, communicate cyber risk effectively to executives and boards, rethink traditional third-party risk practices, and prepare for a future where security leaders must balance innovation with increasingly complex threats.  Takeaways:The speed of change remains one of the biggest challenges facing security leaders today, with AI accelerating both innovation and the barrier to entry for attackers. AI governance starts with visibility. Before organizations can govern AI effectively, they need an inventory of where AI systems and agents actually exist across the business. Citizen development creates opportunities for innovation but also introduces new security responsibilities that many non-technical users may not fully understand. Effective board communication requires focusing on risk, change, and business impact rather than diving into highly technical details that executives may not find actionable. Traditional third-party risk management approaches often rely heavily on questionnaires that may not provide meaningful security insight, highlighting the need for more risk-focused evaluation methods. Security teams are continually playing catch-up as new technologies emerge, while foundational controls such as encryption and access management remain consistently important. Cybersecurity professionals entering the field should embrace AI tools rather than fear them, as familiarity with AI is rapidly becoming a critical skill regardless of technical background. Quote of the Show:“It's impossible to be an expert at everything.” - John Rogers Links: LinkedIn: https://www.linkedin.com/in/johnsrogers/Website: http://www.msci.com Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#19

Foundation First - Michael Myint - Cyber Smokehouse - Episode #19

Most cybersecurity conversations start with technology. Michael Myint starts with the foundation. In this episode of Cyber Smokehouse, Ernie Anderson and Graeme Payne sit down with Michael Myint, a cybersecurity executive whose thirty year career spans Big Four consulting, global enterprises, and high growth healthcare startups. He has built programs from scratch, led organizations through public incidents, and mentored security leaders who have gone on to surpass him. You will walk away with a sharper view of where AI is genuinely changing the threat landscape, why vendor consolidation is coming, whether organizations are ready or not, and what separates the security professionals who rise from the ones who stall. Takeaways:Board communication lives or dies on business relevance. Phishing rates and patch counts belong in the appendix. Metrics tied to revenue, speed to delivery, and product outcomes are what earn executive attention and budget support.AI is disrupting the entry level pipeline in ways the industry has not fully reckoned with. New practitioners who rely on prompt engineering without foundational knowledge will struggle when things break and nobody knows why.Vendor consolidation is coming. The era of niche tools for every sliver of the security stack is giving way to platforms that cover more ground at lower cost, and leaders who get ahead of that shift will be better positioned.Quantum computing combined with AI capabilities is a legitimate long term concern. Nation state actors are already better resourced than most enterprises, and that gap only widens as quantum matures.The CISO is not the department of no. Security leaders who lean on restriction and compliance theater lose credibility quickly. The ones who earn trust show up with solutions and speak the language of the business.Building future leaders requires giving real ownership, not just tasks. Cross training across security functions and evaluating people on program outcomes rather than activity is what develops professionals who can eventually lead on their own.A foundational background still matters before moving into a cybersecurity role. Understanding networking, identity, and how systems actually work provides context that no certification shortcut can replace.Quote of the Show:“"Be curious, dig a lot, be a go-getter, be a problem solver, take ownership."- Michael MyintLinks:LinkedIn: https://www.linkedin.com/in/michaelmyint/Website: https://adapthealth.com/ Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#18

Rethinking Security Risk - Mea Clift - Cyber Smokehouse - Episode #18

Cybersecurity careers are rarely linear, and building effective security leadership requires more than technical expertise alone. In this episode of Cyber Smokehouse, Ernie Anderson and Graeme Payne sit down with Mea Clift, CISO at Cengage, for a conversation about cybersecurity career growth, leadership, curiosity, and risk management. Mea shares insights on how professionals can find their place within the cybersecurity industry, why curiosity is essential for long-term success, and how passion drives deeper expertise. The discussion also explores misconceptions about the CISO role, business impact assessments, security risk, and the realities of operating modern security programs. Outside of cybersecurity, the conversation shifts into Mea’s approach to smoking and grilling, including charcoal setups, smoking techniques, and favorite recipes.  Takeaways:Cybersecurity professionals should find a specialty they’re passionate about. Mea explains that broad interest alone is not enough to build a successful cybersecurity career and encourages people to identify the specific area that excites them most.Curiosity is critical for long-term success in security. The conversation highlights the importance of continuous learning because cybersecurity constantly evolves.Passion helps professionals stand out in competitive hiring environments. Mea discusses how enthusiasm, projects, networking, and deep subject knowledge differentiate candidates during interviews.Business impact assessments are an underrated security control. During the lightning round, Mea identifies business impact assessments as a security control that deserves more attention.Risk remains a major challenge within the security industry. Mea gives a concise answer of “Risk” when asked what the industry is getting completely wrong.There are misconceptions about what CISOs actually do. The discussion touches on common assumptions around the day-to-day work of CISOs and the operational realities behind security leadership roles.Smoking and grilling are part of Mea’s creative outlet outside work. Mea shares details about her charcoal and wood smoking setup, favorite smoking techniques, and favorite  recipes. Quote of the Show:“Life’s too short. You gotta follow your passion.” - Mea Clift Links:LinkedIn: https://www.linkedin.com/in/mea-clift/Website: https://www.cengagegroup.com/ Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#17

Cybersecurity Beyond Compliance - Matthew Mudry - Cyber Smokehouse - Episode #17

What happens when organizations scale rapidly through acquisition while simultaneously navigating AI adoption and evolving cyber risk? In this episode of Cyber Smokehouse, Ernie Anderson and Graeme Payne sit down with Matthew Mudry, CISO at Alera Group, to discuss the operational realities of securing large-scale acquisitions, integrating fragmented environments, and managing cybersecurity risk during periods of aggressive growth. Matthew shares firsthand experiences standardizing security across acquired organizations, balancing business pressure with security due diligence, and navigating the growing complexity introduced by AI technologies. The conversation explores M&A integration challenges, data loss prevention, access control, AI governance, leadership communication, security roadmaps, and the future of the CISO role.  Takeaways:M&A creates significant operational security complexity. Matthew discusses the challenge of integrating acquired businesses into standardized security platforms and processes.Security teams need earlier involvement in acquisitions. The conversation explores how organizations sometimes prioritize business growth before fully understanding integration and security risks.AI introduces both opportunity and risk. Matthew shares concerns around AI misuse, access control, data loss prevention, and adversarial use cases while also discussing opportunities to improve security operations using AI.Access control and DLP remain foundational. The episode repeatedly emphasizes the importance of strong access controls and data protection strategies when adopting AI technologies.Security leaders must communicate effectively with executives. Matthew discusses translating technical risk into measurable business reporting through roadmaps, metrics, and leadership engagement.Strong technical foundations matter for future leaders. Matthew advises aspiring cybersecurity leaders not to rush into management too early and stresses the importance of technical and risk management experience.Quantum computing is becoming a long-term concern. The conversation explores future risks around encryption, legacy data exposure, and long-term data retention. Quote of the Show:“What’s better than fighting AI with AI?” - Matthew Mudry Links: LinkedIn: https://www.linkedin.com/in/matthewmudry/Website: http://www.aleragroup.com Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#16

Modern Cybersecurity Challenges: Explained- Mike Salem - Cyber Smokehouse - Episode #16

Cybersecurity is evolving faster than ever, and leaders are being forced to rethink how they approach risk, resilience, and modern defense strategies. In this episode of Cyber Smokehouse, Ernie Anderson and Graeme Payne sit down with Mike Salem to discuss today’s rapidly changing cyber landscape and the growing influence of AI on both attackers and defenders. Throughout the conversation, Mike shares insights on emerging cyber threats, operational challenges facing security teams, and the importance of adaptability in modern cybersecurity leadership. The discussion also explores how organizations can better prepare for evolving risks while balancing innovation, visibility, and practical security execution. This episode offers valuable perspective for cybersecurity leaders, IT professionals, and organizations navigating constant technological change and increasing security complexity.  Takeaways: • AI is rapidly changing the cybersecurity landscape. The conversation explores how AI is accelerating both offensive and defensive cybersecurity capabilities and increasing the speed of change across the industry. • Security teams must continuously adapt. Mike discusses the operational challenges organizations face as threats evolve faster than traditional security processes. • Visibility and awareness remain critical.The episode highlights the importance of understanding environments, risks, and potential gaps before incidents occur. • Cybersecurity leadership requires flexibility. The discussion emphasizes the need for leaders to remain adaptable while balancing business priorities and security objectives. • Threat actors are evolving quickly. Mike shares perspectives on how modern attackers are becoming more sophisticated and accessible through emerging technologies. • Organizations must focus on practical execution. The conversation reinforces the importance of operationalizing security strategies rather than relying solely on theoretical frameworks. Quote of the Show:“Threat actors are evolving faster than most organizations can react.” -  Mike Salem Links: LinkedIn: https://www.linkedin.com/in/mikesalem2112/Website: http://www.ihstowers.comMike’s Email: mss972@yahoo.com Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#15

Security Fundamentals in an AI-Driven World - Zlatko Unger - Cyber Smokehouse - Episode #15

Tired of the buzzword bingo flooding the cybersecurity industry? So is Zlatko Unger. In this episode of Cyber Smokehouse, Ernie Anderson and Graeme Payne welcome Zlatko Unger, CISO Expert at Wiz, for a no-nonsense conversation that cuts straight through the AI noise and gets back to what actually matters in security. With over 18 years of experience spanning security, risk, privacy, and compliance, Zlatko brings the kind of hard-earned perspective that only comes from building and scaling security programs in the real world. From the growing complexity of identity and access management to the supply chain gaps that keep him up at night, Zlatko lays it all out plainly. You will walk away with a clearer picture of where AI is genuinely useful in security programs, where technical debt is quietly piling up while everyone chases the next shiny thing, and what it takes to lead remote security teams and communicate risk to a board that may not want to hear it. This one is packed with substance, humor, and the kind of candid insight you rarely get on a stage at RSA.  Takeaways:AI hype is creating real operational risk. Organizations are rushing to adopt AI tools without the due diligence needed to understand what they are allowing or what risks are being introduced.Foundational security is being deprioritized. Technical debt keeps accumulating and legacy threats are still getting through because teams are too distracted by what is new to fix what is old.The AI agent space is where the near-term security value lives. Agentic tools that surface information faster and offer action suggestions are more meaningful than the AI-powered SOC marketing dominating the RSA floor.Identity and access management is growing more complex, not less. There is no standard across SaaS platforms for how permissions and scoping work, leaving serious gaps in logs, accountability, and access control.Supply chain and third-party risk still has massive gaps. Security teams often cannot trace where their data goes beyond the first layer of vendors, and AI black boxes embedded in vendor tools are making this harder.Cloud security has matured, but smaller organizations are still the weak point. Larger organizations have developed stronger muscle memory for secure cloud configuration, while smaller businesses are still stumbling into basic misconfigurations.Communicating risk to the board requires speaking their language. Translating technical risk into financial impact and tailoring the message to each stakeholder's function is what gets attention and drives action.Building strong teams means distributing hiring judgment. A committee-based interview process that includes different perspectives and gives staff a real voice in the final decision helps catch what any one interviewer might miss.Remote team culture requires intentional effort. In-person offsites, consistent communication, and encouraging team members to get outside and interact with people are all essential to keeping a remote team healthy.A course correction is coming on AI. Zlatko predicts organizations will hit a wall trying to replace too many functions with AI and will ultimately swing back toward valuing people who know how to use it rather than replacing people with it. Quote of the Show:“Using AI in every way, shape, or form creates a tremendous amount of risk across the organization.” - Zlakto Unger Links:LinkedIn: https://www.linkedin.com/in/zlatkounger/Website: https://www.wiz.io Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#14

Security in the Age of AI Acceleration - David Cross - Cyber Smokehouse - Episode #14

How is AI changing both the threat landscape and the way security teams operate? Today’s guest is a seasoned cybersecurity leader navigating these changes at scale. Introducing David Cross, CISO at Atlassian. David joins Ernie Anderson and Graeme Payne to share how AI is reshaping cybersecurity, from attacker capabilities to internal defense strategies. He discusses how AI is lowering the barrier for attackers, why security teams must adapt to an increasingly fast-moving environment, and how organizations should think about managing risk as new technologies emerge. David also touches on the importance of understanding evolving threats, maintaining strong fundamentals, and ensuring teams are prepared to respond to continuous change.  Takeaways:AI is lowering the barrier for attackers: David explains that AI makes it easier for more individuals to carry out attacks, increasing both the volume and accessibility of threats. The pace of change is accelerating risk: He highlights that the speed at which AI is evolving is creating challenges for security teams trying to keep up. Security teams must continuously adapt: David emphasizes that organizations cannot rely on static defenses and must evolve alongside the threat landscape. Understanding threats is critical to defense:He discusses the importance of knowing how attackers operate in order to build effective security strategies. Fundamentals still matter: Despite new technologies, core security practices remain essential in protecting organizations. AI impacts both offense and defense: He notes that AI is not just a risk, but also a tool that can be used to strengthen security operations. Quote of the Show:“The pace of change is only increasing.” - David Cross Links:LinkedIn: https://www.linkedin.com/in/david-b-cross-b856657/Website: https://atlassian.com/Personal Website: davidcrosstravels.com Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#13

Faster Innovation, Greater Risk - Jason Loomis - Cyber Smokehouse - Episode #13

How do you secure an environment when the technology is evolving faster than teams can keep up? Today’s guest is a cybersecurity leader operating at the intersection of AI, product security, and enterprise scale. Introducing Jason Loomis, CISO at Freshworks. Jason joins Ernie Anderson and Graeme Payne to share why the speed of AI innovation is becoming one of the biggest challenges in cybersecurity today. He dives into how AI is accelerating both development and risk, the growing difficulty of maintaining guardrails in AI-generated code, and why organizations are still struggling to implement governance at scale. Jason also shares a candid perspective on how AI may impact the future of cybersecurity talent, particularly at the entry level, and why continuous learning is becoming non-negotiable for security professionals.  Takeaways:The biggest challenge is simply keeping up. Jason states directly that the pace of change, especially driven by AI, is the hardest problem organizations face today. AI is accelerating both productivity and risk. From a development perspective, AI is increasing output and speed, but from a security perspective, it introduces new challenges around control and governance. Guardrails for AI-generated code are not mature yet. He highlights that while AI can write code, implementing consistent security controls and governance across tools is still difficult and not easily standardized. Entry-level cybersecurity roles are at risk. Jason explains that AI is already replacing lower-level roles like SOC analysts and GRC positions, which may impact long-term talent development. AI could reduce the future talent pipeline. He raises concern that removing entry-level learning opportunities may lead to fewer experienced professionals advancing into senior roles over time. Software supply chain risk is a growing concern. Beyond AI itself, Jason points to supply chain security as a major emerging challenge that organizations must address. AI literacy is becoming mandatory. He makes it clear that security professionals who are not actively learning and using AI risk becoming obsolete in the near future.  Quote of the Show:“Keeping up… it’s just fast, and AI is exponentially making it faster.” - Jason Loomis Links: LinkedIn: https://www.linkedin.com/in/jasonloomis1/recent-activity/images/Website: https://www.freshworks.com/?tactic_id=6909181&utm_source=social&utm_medium=linkedin&utm_campaign=aboutpage&utm_ter Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#12

Foundations Still Define Cybersecurity Success - Merlin Namuth - Cyber Smokehouse - Episode #12

Why do organizations still struggle with cybersecurity despite more tools and innovation than ever before? Today’s guest is a seasoned cybersecurity executive with deep experience across enterprise and public sector environments. Introducing Merlin Namuth, CISO for the City and County of Denver. Merlin joins hosts Ernie Anderson and Graeme Payne to share why foundational security practices continue to be the biggest challenge for organizations today. He dives into why core disciplines like asset management and vulnerability management are often overlooked despite being critical, how AI is both a force multiplier and a growing threat, and why leadership, communication, and continuous learning are essential in cybersecurity. Merlin also shares practical insights on building high-performing teams, developing talent, and staying relevant in an industry that is constantly evolving.  Takeaways:Foundational security practices remain the biggest gap. Merlin emphasizes that organizations still struggle with core areas like hardware asset management, software tracking, and vulnerability management, despite their importance to reducing risk. “Basic” security is not actually easy. He reframes “basic” controls as “foundational” because they are difficult to implement consistently at any scale, regardless of organization size. AI is both a force multiplier and a threat. AI improves detection and response capabilities, but adversaries are also using it to rapidly develop exploits, increasing the pace of threats. Cybersecurity requires constant learning. The field changes rapidly, and professionals must continuously invest time in learning new technologies, compliance changes, and evolving threats. Leadership requires trust, feedback, and self-reflection. Merlin highlights the importance of having a trusted inner circle that can provide honest feedback and help leaders improve over time. Attracting talent requires a strong team culture. In public sector environments where compensation may be lower, promoting the quality of the team and mission helps attract strong candidates. Security programs must align across the business. He discusses working closely with functions like legal and communicating risk in ways that resonate with broader organizational goals. Quote of the Show:“I still see organizations just struggle with what I call the foundational elements of security.” - Merlin Namuth Links: LinkedIn: https://www.linkedin.com/in/merlin-namuth/Website: SeeYourselfHere.org Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550
#11

Cybersecurity Is a Business Conversation - Chris Correia - Cyber Smokehouse - Episode #11

How do you translate cybersecurity from a technical function into a true business priority? Today’s guest is a seasoned cybersecurity leader with deep enterprise experience. Introducing Chris Correia, CEO of CGS CyberDefense. Chris joins hosts Ernie Anderson and Graeme Payne to share how cybersecurity leaders must evolve from technologists into business storytellers who can align security with organizational priorities. He dives into why security conversations need to shift from tools to outcomes, how risk quantification enables better executive decision-making, and why organizational resiliency goes far beyond traditional cyber playbooks. Chris also shares leadership lessons from building teams, investing in the next generation, and creating long-term client relationships rooted in trust and value. Takeaways • Cybersecurity must be communicated in business terms. Chris emphasizes that security leaders need to translate technical concepts into business language to effectively engage executives and boards. • Risk quantification enables better decisions. He explains that framing security investments in terms of financial impact helps shift conversations from emotion to fact-based decision-making. • “Rules before tools” should guide security strategy. Organizations often overinvest in technology without building the right programs. Chris highlights the importance of designing the strategy first, then aligning tools to support it. • Organizational resiliency must extend beyond IT. Resiliency is not just a cybersecurity function. It requires coordination across the entire business, including roles like HR and operations, to ensure preparedness in real scenarios. • Testing and readiness must be continuous. Many organizations test disaster recovery or response plans too infrequently. Chris stresses the need for ongoing, practical testing to build real readiness. • AI must be used, but carefully validated. He notes that while AI is becoming essential, organizations must fact-check outputs and implement guardrails to avoid risk and misuse. • Relationships are central to consulting success. Chris highlights that long-term value comes from relationships, not transactions, and that trust is foundational in the consulting world.  Quote of the Show:“You have to be able to tell the right story to the right audience.” - Chris Correia Links: LinkedIn: https://www.linkedin.com/in/christopher-correia-/?skipRedirect=trueWebsite: https://cgscyberdefense.com/ Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550
#10

Securing What You Can’t See - Clete Taylor - Cyber Smokehouse - Episode #10

How do you secure environments that are constantly changing, distributed, and increasingly difficult to see? Today’s guest is a forward-thinking cybersecurity leader focused on tackling modern visibility and infrastructure challenges. Introducing Clete Taylor, Senior Security Architect at Frost. Clete joins hosts Ernie Anderson and Graeme Payne to explore how evolving environments are reshaping the way organizations approach security. He shares how the shift to cloud and hybrid infrastructure has created blind spots that traditional tools struggle to address. The conversation dives into why visibility is foundational to security, how attackers exploit gaps in awareness, and what organizations must do to adapt. Clete also highlights the importance of proactive strategy, continuous monitoring, and aligning security practices with how modern systems actually operate. Takeaways: • You cannot secure what you cannot see. Modern environments are dynamic and distributed, making visibility the foundation of any effective security strategy. Without clear insight into systems and access, risk increases significantly. • Traditional security models are falling behind. Perimeter-based approaches were built for static environments. Today’s cloud and hybrid infrastructures require adaptive, continuously evolving security strategies. • Complexity creates opportunity for attackers. As systems grow more complex, gaps naturally emerge. Attackers are increasingly targeting these blind spots where monitoring and control are weakest. • Continuous monitoring is no longer optional. Security must operate in real time. Point-in-time assessments are not enough to detect or respond to threats in fast-moving environments. • Alignment between infrastructure and security is critical. Security strategies must reflect how systems are actually built and used. Misalignment creates inefficiencies and increases vulnerability. • Proactive thinking outperforms reactive defense. Organizations that anticipate risks and design for them early are far better positioned than those constantly reacting to incidents. Quote of the Show:“If you don’t have visibility, you’re making decisions in the dark.” - Clete Taylor Links: LinkedIn: https://www.linkedin.com/in/cletetaylor13/Website: cletustaylor.comBook Link: https://www.amazon.com/dp/B0GG5VL3MQ Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#9

Securing Identity in a Cloud-First World - Joe Mendygral - Cyber Smokehouse - Episode #9

How do organizations stay secure when identity, access, and infrastructure are more distributed than ever before? Today’s guest is a seasoned cybersecurity leader focused on modern identity and cloud security challenges. Introducing Joe Mendygral, Senior Director at TBD Cyber. Joe joins hosts Ernie Anderson and Graeme Payne to explore how identity has become the core battleground in cybersecurity. He also delves into how cloud environments, AI, and evolving attack methods are forcing organizations to rethink how they detect and respond to threats. Joe shares practical insights on visibility, detection, and why traditional security approaches are struggling to keep up with modern environments. The conversation highlights the growing importance of understanding user behavior, securing identities, and building adaptive security strategies that evolve alongside threats. Takeaways: • Identity is now the primary attack surface. As organizations move to cloud-first environments, attackers are increasingly targeting identities instead of infrastructure. Securing who has access is now more important than securing where access happens. • Visibility gaps create the biggest risks. Many organizations lack a clear understanding of who has access to what across systems. Without visibility, it becomes nearly impossible to detect or respond to threats effectively. • Detection must evolve beyond traditional methods. Signature-based and perimeter-focused security models are no longer sufficient. Modern environments require behavior-based detection that can identify anomalies in real time. • Cloud complexity increases security challenges. As infrastructure becomes more distributed, security becomes harder to manage. Organizations must adapt their strategies to account for dynamic environments and decentralized access. • AI is changing both offense and defense. AI is enabling faster detection and response, but it is also being used by attackers to scale and automate threats. Security teams must evolve just as quickly to stay ahead. • Security requires continuous adaptation. There is no static solution to cybersecurity. Organizations must continuously refine their strategies, tools, and processes to keep up with an ever-changing threat landscape. Quote of the Show:“If you don’t understand identity and behavior, you don’t understand your risk.” - Joe Mendygral Links: LinkedIn: https://www.linkedin.com/in/joe-mendygral-0846a82/Website: https://www.tbdcyber.com Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#8

AI, Identity, and the Future of Security- Steve Bay - Cyber Smokehouse - Episode #008

How do cybersecurity leaders manage risk, talent, and rapid innovation as AI transforms both threats and defenses? Today’s guest is a seasoned cyber intelligence leader and strategic risk advisor. Introducing Steve Bay, Vice President of Cybersecurity and Chief Information Security Officer at Coretelligent. Steve joins hosts Ernie Anderson and Graeme Payne to share how AI is reshaping the cybersecurity landscape and what leaders must do to stay ahead. He also delves into talent challenges, evolving threat dynamics, and the importance of balancing innovation with governance in a rapidly changing environment. Steve shares insights from his journey into cybersecurity, his experience in intelligence and enterprise security, and his perspective on how organizations can navigate uncertainty while building resilient security programs. Takeaways:AI is the biggest disruptor in cybersecurity today: AI is transforming how both defenders and attackers operate. Organizations must understand how employees are using AI tools and how threat actors are leveraging them to exploit vulnerabilities. Governance of AI is critical but complex: Banning AI is not realistic and can create more risk than it solves. Leaders must focus on thoughtful governance that enables innovation while protecting data and systems. The cybersecurity talent market is evolving rapidly: There is a disconnect between hiring expectations and market reality. Companies want experienced talent at entry-level cost, while skilled professionals still struggle to find the right roles. AI may reshape entry-level career paths: As AI automates more foundational work, organizations must rethink how they develop junior talent and build future cybersecurity leaders. Cost pressure is forcing smarter security strategies: Organizations must balance delivering high-quality security with tight budgets. This requires prioritization, efficiency, and a clear understanding of business risk. Curiosity and adaptability are essential for leaders: Steve highlights that the pace of change requires continuous learning. Leveraging tools like AI for daily awareness can help leaders stay informed without being overwhelmed Quote of the Show:“We need to figure out how to harness AI and maximize it for the good of society, not try to ban it.” - Steve Bay Links: LinkedIn: https://www.linkedin.com/in/steven-bay-8005865/Website: https://www.core.tech Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#7

Translating Cyber Risk for Business Leaders - Jimmy Lummis - Cyber Smokehouse - Episode #007

How can cybersecurity leaders translate technical threats into real business decisions without losing executive alignment or strategic clarity? Today’s guest is a thoughtful cybersecurity strategist and business-focused security leader.  Introducing Jimmy Lummis, Director and Business Information Security Officer at IHG Hotels & Resorts. Jimmy joins hosts Ernie Anderson and Graeme Payne to discuss how modern security leaders must bridge the gap between technical teams and executive leadership. He also explores the realities of cyber risk quantification, the role of AI in modern threat landscapes, and why translating cybersecurity into business language is essential for effective decision making. Takeaways Cybersecurity is ultimately about managing risk, not eliminating it. Jimmy explains that no organization can achieve perfect security. The real responsibility of leaders is determining what level of risk the business is willing to accept and aligning security investments accordingly. Cyber risk must be translated into business language. Technical discussions about vulnerabilities and controls do not resonate with executives. Effective security leaders frame cyber threats in terms of financial impact, operational disruption, and strategic risk. AI introduces both opportunity and new threat vectors. Organizations are racing to adopt AI, but threat actors are also leveraging these tools. Security leaders must balance innovation with responsible oversight and risk awareness. Traditional cybersecurity problems still matter. While emerging technologies grab headlines, many breaches still occur due to longstanding issues like identity management, patching, and basic security hygiene. Security leaders must act as translators between worlds. Jimmy emphasizes the importance of bridging the gap between engineers and executives. Leaders who can interpret technical realities in business terms help organizations make better strategic decisions. Cyber risk quantification helps prioritize security investments. Quantifying risk allows organizations to make informed tradeoffs about where to allocate resources and which threats pose the greatest potential impact. Quote of the Show:“Cybersecurity is not about eliminating risk. It’s about deciding what level of risk the business is willing to accept” - Jimmy Lummis Links: LinkedIn: https://www.linkedin.com/in/jimmylummis/Website: http://www.ihgplc.com Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#6

Security Strategy Beyond Traditional Perimeters - David Nolan - Cyber Smokehouse - Episode #6

In this episode of Cyber Smokehouse, hosts Ernie and Graeme sit down with David Nolan, Principal Advisor at Apex Advisors, to explore how organizations must rethink cybersecurity as digital environments grow more complex and interconnected. David shares why the traditional concept of a network perimeter is rapidly disappearing as organizations adopt cloud platforms, distributed workforces, and connected technologies. As a result, security leaders must move beyond reactive defense and focus on building resilience, visibility, and strategic alignment across the entire digital ecosystem. The conversation explores how cybersecurity must evolve from a purely technical discipline into a business leadership priority, how organizations can anticipate emerging threats, and why security culture plays a critical role in protecting modern systems. Takeaways:Cybersecurity Must Be a Business Priority: Security is no longer confined to the IT department. Organizations that integrate cybersecurity into strategic decision making are better positioned to manage risk and protect critical operations.The Network Perimeter Has Disappeared: With cloud infrastructure, remote work, and third-party integrations becoming the norm, organizations must move beyond perimeter-based security models and focus on identity, access control, and system visibility.Visibility Is the Foundation of Protection: Leaders cannot defend systems they cannot see. Strong monitoring, telemetry, and system awareness allow organizations to detect vulnerabilities and respond faster to emerging threats.Security Culture Starts at the Top: Effective cybersecurity depends on leadership setting expectations around accountability, awareness, and responsible behavior across the organization.Proactive Security Prevents Major Failures: Organizations that prioritize threat modeling, risk assessments, and preventative controls reduce the likelihood and impact of security incidents.Collaboration Strengthens Defense: Cybersecurity today requires coordination between leadership, technology teams, operational stakeholders, and external partners to protect complex digital ecosystems. Quote of the Show:“Security cannot be an afterthought. It has to be built into the way organizations design systems, processes, and culture from the beginning.” - David Nolan Links:LinkedIn: https://www.linkedin.com/in/david-c-nolan/ Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#5

Resilient Healthcare in a Cyber Age - Hugo Lai - Cyber Smokehouse - Episode # 005

Healthcare cybersecurity is no longer just about compliance, it’s about resilience. In this episode of Cyber Smokehouse, hosts Ernie and Graeme sit down with Hugo Lai, Chief Information Security Officer at Temple Health, to explore how healthcare organizations can protect patient care in an era of AI adoption, ransomware threats, and relentless budget pressure. Hugo shares practical insights from leading enterprise security programs inside one of the most operationally complex industries. From managing medical device risk to embedding daily threat intelligence briefings into team culture, this conversation dives deep into what modern cyber leadership looks like when lives are on the line. Key TakeawaysResilience Over Compliance: HIPAA may focus on privacy, but today’s healthcare security must prioritize operational continuity and patient care even during disruption.Budget Discipline Builds Trust: Security leaders who spend intentionally and align with organizational priorities are more likely to secure sustained executive support.AI Requires Guardrails, Not Roadblocks: Instead of blocking AI adoption, security teams must create safe, approved environments that enable responsible use.Operational Preparedness Is Critical: Tabletop exercises, manual fallback training, and daily threat briefings ensure teams are ready when systems fail.Medical Device Security Is Risk Management: Visibility, segmentation, configuration control, and cross-functional collaboration are essential to managing IoT and clinical device risk.Leadership Is Personalization: Understanding individual team members’ motivations and empowering them appropriately drives performance and retention.Learning Never Stops: In a rapidly evolving threat landscape, cybersecurity leaders must invest in continuous learning for themselves and their teams. Quote of the Show:“We cannot completely eliminate all the risks out there, but it’s important that you have a strategy and you’re making sound decisions when managing risks.” Links: LinkedIn: https://www.linkedin.com/in/hugolai/Website: https://www.templehealth.org Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#4

Leading Through Cyber Complexity - Wade Myers - Cyber Smokehouse - Episode # [004]

In this episode of Cyber Smokehouse, hosts Ernie and Graeme sit down with Wade Myers to explore the leadership discipline required to navigate modern cyber risk. Wade shares why complexity is the enemy of effective security programs, how executives must think about tradeoffs instead of perfection, and why clarity, not control, is the real advantage in today’s threat landscape. The conversation dives into decision-making under uncertainty, aligning cybersecurity with business priorities, and the importance of building teams that can operate confidently in high pressure environments. Wade unpacks how security leaders can move beyond compliance thinking and instead focus on meaningful risk management that strengthens resilience across the organization. Takeaways:Cybersecurity is a decision-making discipline, not a toolset. Effective programs are built on sound judgment, prioritization, and alignment with business objectives—not simply the deployment of more technology.Risk cannot be eliminated, only managed intelligently. Leaders must move away from the illusion of total control and instead build frameworks that allow them to evaluate tradeoffs clearly and respond with confidence.Complexity is the hidden threat. Overly layered controls, unclear ownership, and bloated processes create blind spots. Simplification improves visibility, accountability, and response speed.Clarity at the executive level determines program success. When leadership understands what matters most, resources are deployed strategically instead of reactively.Security must support business velocity. The strongest programs protect critical assets while enabling innovation and operational momentum.Resilience outperforms perfection. Organizations that plan for disruption, rehearse response, and empower teams to act decisively outperform those chasing zero incidents.Culture shapes security outcomes. Clear communication, ownership, and psychological safety allow teams to raise risks early and act before issues escalate. Quote of the Show:“Cybersecurity isn’t about eliminating risk, it’s about making intelligent decisions under uncertainty.” Links: LinkedIn: https://www.linkedin.com/in/wade-myers-b287833/Website: https://www.equifax.com/ Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
Previous Page

Displaying 1 - 20 of 24 in total

Next Page