CISO Tradecraft®
4.8(49)

CISO Tradecraft®

by G Mark Hardy & Ross Young

293 episodesLatest 2 days agoEN

You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level.

© Copyright 2025, National Security Corporation. All Rights Reserved

© Copyright 2025, National Security Corporation. All Rights Reserved

Recent reviews on Apple Podcasts (4)
  • So informative and logically organized

    This podcast has been instrumental in transforming how I think about cyber and business risk. There’s not a lot of other podcasts that I’ve seen or heard from that enables you to go wider or deeper in your understanding. Thank you for the effort y’all put into these and what you’re doing for our community.

    JoshSommers ·

  • Critical Information for Our Critical Infrastructure

    The nature of the internet makes it incumbent on every organization to prevent intrusions, be they foreign or domestic. Corporate cybersecurity is not a business concern. It is a national Security concern. For this reason, the information conveyed in this podcast should be on every cybersecurity professional’s listening list , from CISO to entry level security associateS just beginning their career. There is no unimportant person when it comes to cybersecurity. Anyone who uses a computer connected to the internet can reign down catastrophe on an organization. It is up to cybersecurity personnel to prevent that from happening. G. Mark Hardy seems almost chosen to be the one that helps corporations stay safe. It doesn’t hurt that he has a calm, reassuring, voice that conveys a message that this is doable, and that you are the one who can do it.

    PBinNewJ ·

  • A great resource for those in the cyber world

    This is such a great casual podcast for those looking to work their way into management in the cyber world. I recommend this to anyone who is interested!!

    idavis7 ·

  • Really interesting podcast for people wanting to be a CISO

    There are a lot of podcasts on cyber security. This one has something unique. The creators have a natural energy that resonates well and I enjoy their thoughts. What is most impressive is learning how to become a ciso. There is no silver bullet but the points they bring up are really interesting. I look forward to hearing more episodes

    Financialadventure ·

View all reviews on Apple Podcasts

Episodes (293)

  1. Legal Developments Every CISO Needs to Know with Larry Dietz - #293

    Jul 20, 202641m#293

    Three major legal changes. One question every CISO should be asking: Is your cybersecurity program ready? Congress let a key FISA surveillance authority expire. The Supreme Court raised the bar on geofence warrants. The

  2. The Business Risk Playbook CISOs Use to Win - #292

    Jul 13, 202641m#292

    What separates great CISOs from everyone else? It isn't knowing more about CVEs, ransomware, or the latest security tools. It's understanding the business. In this episode of CISO Tradecraft, Ross Young and G Mark Hardy

  3. The CISO Mind Map Has Evolved for the AI Era - #291

    Jul 6, 202641m#291

    How has the role of the CISO changed over the last 15 years? In this episode of CISO Tradecraft, G. Mark Hardy interviews Rafeeq Rehman, creator of the CISO Mind Map, to discuss its latest update and the biggest challeng

  4. Harvest Now, Decrypt Later (with Marcus Sachs) - #290

    Jun 29, 202641m#290

    Nation-state adversaries are vacuuming up encrypted traffic today, waiting for quantum computers to decrypt it tomorrow. This attack strategy, "Harvest Now, Decrypt Later," isn't theoretical. It's happening right now. G

  5. #289 - What's the Best Career Move After Being a CISO? (with Gary Hayslip)

    Jun 22, 202643m#289

    On this episode of CISO Tradecraft, host G Mark Hardy talks with Gary Hayslip about cybersecurity career growth beyond the traditional CISO “apex,” drawing on Hayslip’s 25+ years across military service, US Navy civil se

  6. #288 - How to Break Into Cybersecurity Through GRC (with Steve McMichael)

    Jun 15, 202639m#288

    In this CISO Tradecraft episode, host G Mark Hardy interviews Steve McMichael, author of "How to Break into GRC: Mindset, Methods, and Skills," about entering cybersecurity through governance, risk, and compliance. McMic

  7. #287 - Cybersecurity Insights You'll Want to Hear (with Michael Hammer)

    Jun 8, 202645m#287

    Want to move from "security expert" to "trusted business leader"? Join G. Mark Hardy and Michael Hammer. The mind behind the core of DMARC , for 40 years of hard-won wisdom on navigating the CISO role, This episode is a

  8. #286 - AI-Native Security (with Nishant Doshi & Saro Subbiah)

    Jun 1, 202645m#286

    What if your next breach isn't caused by a human... but by an AI agent acting exactly as instructed? Cyberhaven's CEO (Nishant Doshi) and SVP of Engineering (Saro Subbiah) reveal why AI is a true zero-to-one shift, why e

  9. #285 - Passwordless Authentication (with Nishant Kaushik)

    May 25, 202642m#285

    In this discussion, G. Mark Hardy and Nishant Kaushik explore the necessity of moving beyond traditional passwords, which they define as the original sin of cybersecurity due to their vulnerability to credential stuffing

  10. #284 - Lessons Learned from SQL Slammer to AI Agents (with Aaron Turner)

    May 18, 202645m#284

    What can today’s CISOs learn from the chaos of Code Red and SQL Slammer? In this episode, G Mark Hardy interviews Aaron Turner about what it was like responding inside Microsoft during two of the most infamous cyber outb

  11. #283 - Leadership Lessons and the Art of the Performance (with Chris Brogan)

    May 11, 202647m#283

    In this episode of the CISO Tradecraft podcast, host G Mark Hardy interviews early tech adopter Chris Brogan to explore the intersection of high-performance leadership and effective communication. Drawing from his interv

  12. #282 - Top 10 Agentic AI Attacks (with Rock Lambros)

    May 4, 202645m#282

    In this CISO Tradecraft episode, host G Mark Hardy interviews recovering CISO Rock Lambros (Zenity) about securing Agentic AI and the emerging risks beyond LLM hallucinations. Lambros recounts his path from Oracle develo

  13. #281 - SIEM Secrets They Don’t Tell You (with Anton Chuvakin & Alex Hurtado)

    Apr 27, 202648m#281

    In this CISO Tradecraft episode, host G Mark Hardy talks with Anton Chuvakin and Alex Hurtado about how SIEM programs fail and how organizations overspend when implementations prioritize dashboards or compliance over act

  14. #280 - Mythos and the Future of Vulnerability Operations (with Gadi Evron)

    Apr 20, 202643m#280

    In this episode of CISO Tradecraft, host G Mark Hardy speaks with Gadi Evron about the paper “The AI Vulnerability Storm Building: A Mythos Ready Security Program,” a community-driven draft produced in days with extensiv

  15. #279 - AI Readiness (with JP Bourget)

    Apr 13, 202644m#279

    On CISO Tradecraft, host G Mark Hardy welcomes back JP Bourgeet to discuss what “AI readiness” means for organizations, framing it as both a data governance challenge and a change-management problem. JP defines readiness

  16. #278 - RSAC Takeaways: AI SOC, Agent Security, and What Cyber Marketing Gets Wrong

    Apr 7, 202645m#278

    In this CISO Tradecraft episode, G Mark Hardy, Ross Young, and Andy Ellis share RSAC insights from the vendor floor, including Andy’s effort to visit about 607 booths. They highlight dominant themes like AI SOC offerings

  17. #277 - From SaaS to AI Agents: Gone in 60 Seconds

    Mar 30, 202639m#277

    In this CISO Tradecraft episode, co-hosts G Mark Hardy and Ross Young discuss how large language models are transforming software development and shifting cybersecurity from buying Software as a Service to “Service as So

  18. #276 - How is AI Reshaping Fraud (with Brian Long)

    Mar 23, 202640m#276

    In this episode of CISO Tradecraft, host G Mark Hardy speaks with Brian Long, CEO and co-founder of Adaptive Security, about how AI is accelerating and scaling social engineering through deepfakes, OSINT-driven personali

  19. #275 - How to Secure Vibe Code (with Shahar Man)

    Mar 16, 202645m#275

    In this CISO Tradecraft episode, host G Mark Hardy interviews Shahar Man of Backslash Security about the rapidly expanding attack surface created by AI-driven “vibe coding” tools like Claude Code, Cursor, and Copilot. Sh

  20. #274 - The State of Stress in Cyber (with Steve Shelton)

    Mar 9, 202644m#274

    In this CISO Tradecraft episode, host G Mark Hardy interviews Steve Shelton ( https://www.linkedin.com/in/greenshoesteve/ ) of Green Shoe Consulting about the “State of Stress in Cybersecurity 2025” report and why burnou

  21. #273 - Creating a Wisdom-Led SOC (with Oren Saban)

    Mar 2, 202645m#273

    Your SOC is drowning in alerts, false positives, and static tuning, while attackers evolve faster than your team can respond. Analysts burn out chasing noise. Real threats slip through. And traditional metrics reward tic

  22. #272 - Data Centric Platform Play (with EJ Pappas)

    Feb 23, 202659m#272

    In this episode of CISO Tradecraft, host G Mark Hardy speaks with EJ Pappas of PKWARE and Ross Young about why AI-driven threats demand a shift from platform-centric security to a data-centric strategy . CISOs still stru

  23. #271 - A Life of Service (with Chris Inglis)

    Feb 16, 202652m#271

    In this special episode of CISO Tradecraft, host G Mark Hardy welcomes Chris Inglis, former National Cyber Director and career public servant, to delve into a wide-ranging conversation about cybersecurity leadership, pub

  24. #270 - And What is Truth?

    Feb 3, 202631m#270

    Can you still tell what’s true on the internet or does everything feel questionable now? That confusion isn’t accidental. Disinformation, deepfakes, and cyber deception are being used deliberately to manipulate attention

  25. #269 - Changing Third Party Risk Management (with Nate Lee)

    Jan 26, 202634m#269

    Third-party risk management has become a time-consuming, frustrating exercise. Security teams and vendors alike are buried under long, repetitive TPRM questionnaires that often miss what actually matters. Buyers struggle