38 episodes

The monthly podcast for security professionals, by security professionals.Two self proclaimed grumpy security professionals talk security risk, how they’ve managed it in the past and forward looking discussions with guests working in information security and risk management.

Caffeinated Risk McCreight & Leece

    • Business
    • 5.0 • 8 Ratings

The monthly podcast for security professionals, by security professionals.Two self proclaimed grumpy security professionals talk security risk, how they’ve managed it in the past and forward looking discussions with guests working in information security and risk management.

    Contingency Planning, Cyber Resilience and Incident Response

    Contingency Planning, Cyber Resilience and Incident Response

    Regulatory frameworks from PCI-DSS to NERC-CIP  to  the newly minted NIST CSF 2.0 each require organizations of all sizes to have cyber incident response plans.  Most of us who have spent any time in cubicle filled office towers are familiar with fire drills to clear the building and gather staff at muster points, and that is as close as we get to the real thing.  Unfortunately that same lucky streak will   Unlike a fire drill, recent research estimates 85%  of businesses will expereince a cyber incident annually,  and many will find short-comings in their incident response plan.

    This episode explores a couple of recent news-worthy Canadian Cyber incidents, challenges with incident response plans and as always, how to use ESRM principles to further your program, even in a time of crisis. 

    • 28 min
    The Business Context of Cyber Resilience with Steven J Ross

    The Business Context of Cyber Resilience with Steven J Ross

    Those running a business today who have not experienced disruption due to cyber issues or attacks know it is only a matter of time. Even if their organization is not directly targeted, the  modern marketplace comprised of multiple, interconnected  supply chains, means impact is unavoidable but this episode's guest, Steven J Ross contends planning, design and clear priorities can provide mitigating resilience.

    Steven J Ross, executive principal of Risk Masters International, is a recognized cyber security expert, specializing cyber resilience, recovery and  business continuity.   His decades of experience come through loud and clear with a somewhat unflinching perspective on the current digital threat landscape and the impact on organizations and individuals.  In addition to leading a boutique risk management practice helping Finance, Health care, Defense and more,  Mr. Ross has been the author of one of ISACA Journal's most read columns since 1998.

    • 30 min
    Building a Cyber Risk Management Program with Brian Allen

    Building a Cyber Risk Management Program with Brian Allen

    The U.S. Security Exchange Commission defined new rules for cyber risk matters facing publicly traded corporations in July of 2023.  Although the SEC's mandate is limited to publicly traded companies in the United States, where one regulator goes others are apt to follow.  Brian Allen is the co-author of a brand new book putting form, structure and traceability around the SEC mandated requirement for a Cyber Risk Management Program.   Mr. Allen was on of the original creators and advocates of the ESRM framework first published in 2013, and has been practicing security risk management throughout his career. 

    Caffeinated Risk is very please to bring a very candid conversation with a true thought leader in the risk management field to our ever growing family of listeners. 

    • 30 min
    CyberPHA - OT Risk management With John Cusimano

    CyberPHA - OT Risk management With John Cusimano

    The ISA 99 standards body is one of the most recognized authorities on cyber physical security covering many aspects of a cyber security management system for industrial control systems including risk management.  This episode features John Cusimano, former chairman of the ISA subcommittee  responsible for authoring the risk management portion of the standard 62443-3-2:2020  Mr. Cusimano takes us back to the origins of the OT specific risk assessment process, originally dubbed CyberPHA,  we also explore how the methodology can be managed and percieved at different levels of the organization as well as how this approach can safely carry organizations into a future that includes cloud computing.

    John is currently the Vice President for Operational Technology Security at Armexa, more than 30 years experience in OT and one of the early thought leaders in this unique areas of cyber security and risk management.

    • 31 min
    Science, Crime and Workforce Development with Dr. Martin Gill

    Science, Crime and Workforce Development with Dr. Martin Gill

    Security and crime are often in close proximity but not always studied together. This month's episode features Martin Gill a criminologist who made the study of crime and security his life's work.  After a decade as a lecturing professor at the University of Leichester,  Mr. Gill started Perpetuity Research in 2002 and continues to provide very high quality research, both qualitiative and quantitiative,  on what works -- and more importantly what does not --  on many different areas of the security field.   

    In addition to leading the annual Security Research Initiative reports, Martin Gill is also the a contributing author and  editor of many criminology and security textbooks including  "The Handbook of Security" -- now in it's third edition. 

    • 31 min
    ESRM a Decade In and The Emergent Threat Landscape

    ESRM a Decade In and The Emergent Threat Landscape

    Post GSX conference, which  included an in-depth review of ESRM and an interview with former U.S. president George W Bush, this episode considers how enterprise security risk management has stood the test of time as well as how risk analysis will need to evolve . 

    Financial receptors can be found in almost every organizational risk matrix but how do those decisions change with modern ransomware attacks? How does a threat intelligence program contribute to organizational defense and resilience?

    • 29 min

Customer Reviews

5.0 out of 5
8 Ratings

8 Ratings

K.7333 ,

Great 1st episode

Enjoyed the first episode. Looking forward to more. Keep them coming.

Top Podcasts In Business

Money Stuff: The Podcast
Bloomberg
The Diary Of A CEO with Steven Bartlett
DOAC
The Prof G Pod with Scott Galloway
Vox Media Podcast Network
The Business of Doing Business with Dwayne Kerrigan
Dwayne Kerrigan
In Good Company with Nicolai Tangen
Norges Bank Investment Management
Business Wars
Wondery