40 episodes

The monthly podcast for security professionals, by security professionals.Two self proclaimed grumpy security professionals talk security risk, how they’ve managed it in the past and forward looking discussions with guests working in information security and risk management.

Caffeinated Risk McCreight & Leece

    • Business
    • 5.0 • 8 Ratings

The monthly podcast for security professionals, by security professionals.Two self proclaimed grumpy security professionals talk security risk, how they’ve managed it in the past and forward looking discussions with guests working in information security and risk management.

    Resilience and I.R. Lessons Learned (the hard way) - with Adam McMath

    Resilience and I.R. Lessons Learned (the hard way) - with Adam McMath

    Almost all incident response plans include a "lessons learned" step, and in the post adrenalin phase that follows many breaches, reviewing what worked and what needs improving doesn't excite a lot of people. Adam McMath is clearly the exception, leading incident response activities in both the cyber realm and physical. How do resilience and incident response lessons learned while literally fighting fires translate into risk management practices within cyber security, is a go...

    • 34 min
    ESRM a Transformation Catalyst with Radek Havlis

    ESRM a Transformation Catalyst with Radek Havlis

    Amongst the industry verticals classified as critical infrastructure, few would argue that telecommunications belongs in the top that list, placing even more weight on a risk management program due to cascading impacts. Consequently, safe reliable operations are essential for success while continuing to grow in a highly competitive marketplace. A security risk management challenge across many dimensions that has become an ESRM success story. This episode features Radek Havlis, Vice...

    • 29 min
    Contingency Planning, Cyber Resilience and Incident Response

    Contingency Planning, Cyber Resilience and Incident Response

    Regulatory frameworks from PCI-DSS to NERC-CIP to the newly minted NIST CSF 2.0 each require organizations of all sizes to have cyber incident response plans. Most of us who have spent any time in cubicle filled office towers are familiar with fire drills to clear the building and gather staff at muster points, and that is as close as we get to the real thing. Unfortunately that same lucky streak will Unlike a fire drill, recent research estimates 85% of b...

    • 28 min
    The Business Context of Cyber Resilience with Steven J Ross

    The Business Context of Cyber Resilience with Steven J Ross

    Those running a business today who have not experienced disruption due to cyber issues or attacks know it is only a matter of time. Even if their organization is not directly targeted, the modern marketplace comprised of multiple, interconnected supply chains, means impact is unavoidable but this episode's guest, Steven J Ross contends planning, design and clear priorities can provide mitigating resilience.Steven J Ross, executive principal of Risk Masters International, is a reco...

    • 30 min
    Building a Cyber Risk Management Program with Brian Allen

    Building a Cyber Risk Management Program with Brian Allen

    The U.S. Security Exchange Commission defined new rules for cyber risk matters facing publicly traded corporations in July of 2023. Although the SEC's mandate is limited to publicly traded companies in the United States, where one regulator goes others are apt to follow. Brian Allen is the co-author of a brand new book putting form, structure and traceability around the SEC mandated requirement for a Cyber Risk Management Program. Mr. Allen was on of the original creators a...

    • 30 min
    CyberPHA - OT Risk management With John Cusimano

    CyberPHA - OT Risk management With John Cusimano

    The ISA 99 standards body is one of the most recognized authorities on cyber physical security covering many aspects of a cyber security management system for industrial control systems including risk management. This episode features John Cusimano, former chairman of the ISA subcommittee responsible for authoring the risk management portion of the standard 62443-3-2:2020 Mr. Cusimano takes us back to the origins of the OT specific risk assessment process, originally dubbed ...

    • 31 min

Customer Reviews

5.0 out of 5
8 Ratings

8 Ratings

K.7333 ,

Great 1st episode

Enjoyed the first episode. Looking forward to more. Keep them coming.

Top Podcasts In Business

The Diary Of A CEO with Steven Bartlett
DOAC
The Prof G Pod with Scott Galloway
Vox Media Podcast Network
The Ramsey Show
Ramsey Network
Planet Money
NPR
The Canadian Investor
Braden Dennis & Simon Belanger
PBD Podcast
PBD Podcast

You Might Also Like

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
Risky Business News
risky.biz
Cyber Security Headlines
CISO Series
Cybersecurity Today
Howard Solomon
CyberWire Daily
N2K Networks
Economist Podcasts
The Economist