

Defense in Depth
David Spark, Steve Zalewski, Geoff Belknap
Defense in Depth promises clear talk on cybersecurity's most controversial and confusing debates. Once a week we choose one controversial and popular cybersecurity debate and use the InfoSec community's insights to lead our discussion.
Episodes
Mentioned books

May 23, 2024 • 29min
How Do We Build a Security Program to Thwart Deepfakes?
Russ Ayers, SVP of Cyber and Deputy CISO at Equifax, dives into the rising threat of deepfakes and their implications for security. He discusses how AI is blurring the lines between real and fake, creating challenges for identity verification. The conversation highlights the need for advanced detection methods and the creation of new roles like ‘Reality Auditor.’ Russ emphasizes the urgent importance of re-establishing trust in communication as deepfake technology alters our perceptions and legal standards.

May 16, 2024 • 28min
Where Are Secure Web Gateways Falling Short?
Vivek Ramachandran, Founder of SquareX, discusses the effectiveness of Secure Web Gateways in the modern enterprise. Topics include challenges in adapting to browser evolution, the need for better solutions, and the role of SquareX in detecting and mitigating web attacks in real-time.

May 9, 2024 • 31min
Understanding the Zero-Trust Landscape
Richard Stiennon, Chief research analyst, IT-Harvest, discusses the hype and challenges of zero-trust solutions in cybersecurity. They delve into defining zero trust accurately, highlighting the importance of transparency. The podcast explores the risks of vendor dependency and the need for innovative frameworks in cybersecurity product selection.

May 2, 2024 • 35min
Scaling Least Privilege for the Cloud
Sandy Bird, Co-founder and CTO of Sonrai Security, joins the podcast to discuss the challenges of scaling least privilege in the cloud. Topics include automating identity security, optimizing cloud access control, and the evolution of attribute-based access control. Discover the importance of just-in-time access permissions and prioritizing assets for enhanced security.

Apr 25, 2024 • 35min
Should CISOs Be More Empathetic Towards Salespeople?
Emily Heath, general partner at Cyberstarts, joins the podcast to discuss the relationship between CISOs and sales representatives. They delve into the challenges CISOs face with aggressive sales tactics, emphasizing the necessity of empathy and authenticity in sales interactions. The conversation highlights the importance of setting boundaries, providing strategic feedback, and building relationships based on trust and value.

Apr 18, 2024 • 30min
Managing Data Leaks Outside Your Perimeter
Developer advocate Mackenzie Jackson discusses managing data leaks outside your perimeter, addressing the challenges of third-party leaks, the need for security-conscious culture in software development, securely managing secrets and credentials, proactive measures like scanning code repositories for leaks, and safeguarding keys with tools like Gigi Shield and hasmysecretleaked.

Apr 11, 2024 • 36min
What Are the Risks of Being a CISO?
Guest Phil Davis, healthcare cybersecurity attorney, discusses the risks and responsibilities of CISOs in today's climate. Topics include liability, balancing responsibility and authority, and the evolving role of CISOs in organizations. Emphasis on security accountability, regulatory challenges, and the transition to cybersecurity attorney.

Apr 4, 2024 • 31min
Onboarding Security Professionals
Former CISO, Paul Connelly, discusses the crucial role of onboarding new cybersecurity talent, emphasizing the need for effective training and avoiding common mistakes. Strategies include fostering engagement, cross-team collaboration, and early exposure to different departments to create a positive onboarding experience.

Mar 28, 2024 • 29min
How to Improve Your Relationship With Your Boss
Jerry Davis, division director for cyber defense at Truist Bank, discusses the importance of building relationships with your boss to advance your cyber career. Topics include developing soft skills, effective communication strategies, setting clear expectations, and mastering leadership dynamics for success in the workplace.

5 snips
Mar 21, 2024 • 28min
Improving the Responsiveness of Your SOC
Exploring the challenges of integrating new tools in a SOC and the importance of readiness measures. Discussing the shift from past events to current activities, focusing on speed and measurable outcomes. Highlighting the role of Security Orchestration in boosting SOC efficiency. Delving into the shift towards behavioral monitoring in cloud environments. Reflecting on the ineffectiveness of current security measures and the need for proactive actions.


