PodcastsBusinessCISO Tradecraft®

CISO Tradecraft®

G Mark Hardy & Ross Young
CISO Tradecraft®
Latest episode

537 episodes

  • CISO Tradecraft®

    #284 - Lessons Learned from SQL Slammer to AI Agents (with Aaron Turner)

    18/05/2026 | 45 mins.
    What can today’s CISOs learn from the chaos of Code Red and SQL Slammer?
    In this episode, G Mark Hardy interviews Aaron Turner about what it was like responding inside Microsoft during two of the most infamous cyber outbreaks in history.
    Aaron shares firsthand stories from the era when SQL Slammer infected at least 75,000 systems in roughly 10 minutes, exposing massive gaps in patch management, security QA, firewall design, and enterprise readiness. He explains how Microsoft’s early security culture operated, how major incidents and source-code theft forced change, and why many of the same mistakes are now reappearing in enterprise AI adoption.
    The conversation connects the lessons of Code Red and Slammer directly to today’s AI security challenges, including:
    Unauthenticated MCP servers and weak authorization models
    AI accelerating exploit development and vulnerability discovery
    Why the traditional “patching game” no longer scales
    The growing importance of identity security, ITDR, SASE, and developer controls
    How CISOs should think about technical debt and legacy modernization
    Why serverless and cloud-native architectures may become security necessities
    If you’re a CISO, deputy CISO, security architect, or aspiring security leader navigating the risks of AI-driven attacks, this episode provides practical lessons from one of the most important eras in cybersecurity history and why those lessons matter even more today.
    Aaron Turner's Linkedin - https://www.linkedin.com/in/aaronrturner/
  • CISO Tradecraft®

    #283 - Leadership Lessons and the Art of the Performance (with Chris Brogan)

    11/05/2026 | 47 mins.
    In this episode of the CISO Tradecraft podcast, host G Mark Hardy interviews early tech adopter Chris Brogan to explore the intersection of high-performance leadership and effective communication. Drawing from his interviews with Navy SEALs and his tenure as a Chief of Staff, Brogan emphasizes that leadership is essentially the management of options and the cultivation of repetitive training to build a reliable team base. The discussion highlights the necessity of aligning staff roles with business needs, which sometimes requires the difficult but professional decision to let individuals go when they no longer fit the objective. Both experts stress that fully qualifying personnel for their next level of responsibility is a vital duty for any leader aiming for organizational excellence. Ultimately, the conversation advocates for authenticity, a willingness to fail forward, and the use of technology to foster genuine human interaction.
    Chris Brogan's LinkedIn - https://www.linkedin.com/in/cbrogan/
  • CISO Tradecraft®

    #282 - Top 10 Agentic AI Attacks (with Rock Lambros)

    04/05/2026 | 45 mins.
    In this CISO Tradecraft episode, host G Mark Hardy interviews recovering CISO Rock Lambros (Zenity) about securing Agentic AI and the emerging risks beyond LLM hallucinations. Lambros recounts his path from Oracle developer to CISO and AI standards work, then explains how agentic AI increases risk by connecting models to tools and actions. They discuss agentic AI supply chain attacks, including backdoored LiteLLM packages on PyPI and a compromised Amazon Q update, and the resulting shift from “patch fast” to more cautious dependency controls. The conversation highlights the OWASP Top 10 for Agentic Applications 2026, covering threats like goal hijack, tool misuse, identity/privilege abuse, memory/context injection, insecure inter-agent communication, cascading failures, human trust exploitation, and rogue agents, concluding with practical steps: inventory, kill switches, least agency, intent gates, and observability.

    OWASP Top 10 for Agentic Applications -
    https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/
  • CISO Tradecraft®

    #281 - SIEM Secrets They Don’t Tell You (with Anton Chuvakin & Alex Hurtado)

    27/04/2026 | 48 mins.
    In this CISO Tradecraft episode, host G Mark Hardy talks with Anton Chuvakin and Alex Hurtado about how SIEM programs fail and how organizations overspend when implementations prioritize dashboards or compliance over actionable detection engineering and collecting the right data. They share costly war stories ranging from multi-million and eight-figure deployments that became expensive “log toilets” or missed incidents due to data rationing and gaps, to mid-market teams burned by next-gen startup SIEMs going end-of-life and forcing replatforming. The discussion covers why Gartner Magic Quadrants can be useful depending on organizational context, the tradeoffs of decoupled/hybrid SIEM and security data lake architectures (cost, coverage, vendor management, and real-time detection limits), migration and egress/lock-in concerns, emerging AI/agentic SOC models and pricing, and the need to define requirements and measure effectiveness with realistic detection testing metrics.
  • CISO Tradecraft®

    #280 - Mythos and the Future of Vulnerability Operations (with Gadi Evron)

    20/04/2026 | 43 mins.
    In this episode of CISO Tradecraft, host G Mark Hardy speaks with Gadi Evron about the paper “The AI Vulnerability Storm Building: A Mythos Ready Security Program,” a community-driven draft produced in days with extensive input from security leaders. Evron explains how advances in LLMs and agents are accelerating vulnerability discovery and exploitation, shrinking time-to-exploit assumptions and likely increasing the volume of real vulnerability reports and patches. They discuss separating hype from real risk, the impact of Anthropic’s Mythos and limited access via Project Glasswing, and what CISOs should do now: adopt agents to operate at machine speed, use them defensively to find issues, build “vuln ops” capabilities, secure coding agents in the enterprise, and communicate shifting risk metrics to boards. They also preview the next Unprompted conference planned for September.

    VulnAxis - https://vulnaxis.com/
    Gadi Evron - https://www.linkedin.com/in/gadievron/
    Knostic - https://www.knostic.ai/
    The AI Vulnerability Storm Paper - https://labs.cloudsecurityalliance.org/mythos-ciso/
    Unprompted - https://unpromptedcon.org/
More Business podcasts
About CISO Tradecraft®
You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level. © Copyright 2025, National Security Corporation. All Rights Reserved
Podcast website

Listen to CISO Tradecraft®, The Money Café with Alan Kohler and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features