

Caffeinated Risk
McCreight & Leece
The monthly podcast for security professionals, by security professionals.Two self proclaimed grumpy security professionals talk security risk, how they’ve managed it in the past and forward looking discussions with guests working in information security and risk management.
Episodes
Mentioned books

9 snips
Jan 25, 2024 • 30min
Building a Cyber Risk Management Program with Brian Allen
Brian Allen, co-author of a new book on Cyber Risk Management Program, discusses the SEC mandated requirement for cyber risk management. Topics include the framework of a cyber risk management program, balancing risk-informed decision making, and the significance of understanding the role of security professionals.

6 snips
Dec 14, 2023 • 32min
CyberPHA - OT Risk management With John Cusimano
John Cusimano, former chairman of the ISA subcommittee, talks about the origins of the OT-specific risk assessment process, managing and perceiving the methodology, and the future of cloud computing. They also discuss the integration of engineering disciplines in cyber risk management, involving subject matter experts in the risk assessment process, and the significance of collaboration and tailoring the process. The chapter on understanding a risk-based approach in OT security programs emphasizes the importance of baseline controls.

Nov 23, 2023 • 32min
Science, Crime and Workforce Development with Dr. Martin Gill
Explore the intersection of security and crime with criminologist Martin Gill. Learn about evidence-based security practices, the evolving security industry landscape, and the importance of understanding security from an offender's perspective. Discover the significance of effective security measures, professional training, and collaboration within the security industry.

Sep 28, 2023 • 30min
ESRM a Decade In and The Emergent Threat Landscape
Former U.S. president George W Bush discusses ESRM, ransomware, and threat intelligence. The podcast explores the evolution of risk management, financial decisions in the face of cyber attacks, and the importance of resilience in cybersecurity.

Aug 24, 2023 • 36min
Business Enablement using Converged Risk Management with Michael Lashlee
A discussion with Michael Lashlee covers the benefits of physical and cyber security departments working together, drawing insights from the US Marines and Secret Service. They explore how technology supports specialists in keeping client data safe and address the cyber skills talent shortage. Topics include enterprise resilience, protecting financial transactions, initiatives to address the cybersecurity workforce shortage, and forming adaptive teams for effective security solutions.

7 snips
Jul 27, 2023 • 32min
Interpreting Risk within a Regulatory Context with Terry Freestone
Explore Calgary's history as an ICS cyber hub, Terry Freestone's journey in security risk management, and his four-point strategy for risk mitigation. Learn about the mindset shift to cybersecurity, navigating risks in business operations, and balancing time and risk analysis in security management.

Jun 29, 2023 • 31min
2023 Summer Show
Exploring evolving trends in cybersecurity practices, the importance of trust in risk management advisory, earning executive trust for proactive planning in cloud services, and diversifying skill sets for resilience in security programs.

May 25, 2023 • 31min
ESRM and Data Science with Rachelle Loyear
Rachelle Loyear discusses the fusion of data science and security, emphasizing the incorporation of human behavior in risk assessment. Topics include cyber crime risks, data analysis in security strategies, future of data sharing, automation in risk management, and reflections on ESRM evolution.

Mar 23, 2023 • 8min
Attack Tree Calibration with Terry Ingoldsby
Threat modeling expert discusses integrating expertise into risk assessment, no AI magic in identifying threats. Exploring fusion of metrics and opinions in attack tree modeling, analyzing cybersecurity architecture using historical attacks for security assessment.

8 snips
Feb 23, 2023 • 38min
FAIR and ESRM, exploring common ground with Jack Freund
Dr. Jack Freund, risk management thought leader, discusses quantifying risk, breach reports, cultural change in organizations, and prioritizing security efforts. Insightful and humorous, he shares his expertise in risk management with the hosts.


