Cybersecurity Ecosystem Show

Cybersecurity Ecosystem Show

The Cybersecurity Ecosystem Show connects the full spectrum of the industry: practitioners, investors, vendors, regulators, and everyone in between — because the more we learn from each other, the stronger we become.

  1. Sep 24

    Thank Ransomware for Your Seat at the Table

    Jim Mapes is a practicing CISO, advisor, and adjunct professor who has worked in security since the late 1990s, when the field was called information security and security teams could not get a meeting with the CIO. In this conversation, he explains how the industry earned its current board-level standing and what security leaders should do with it. Jim identifies governance as cybersecurity's biggest area of progress, now formalized in NIST 800-53 revision 5 and CSF 2.0, and explains the principle behind effective executive communication: companies do not exist to be secure, so security has to be framed as enabling the business objective with the least risk possible. He credits ransomware with changing executive awareness, because it made operational disruption a universal exposure regardless of what data an organization holds. On board communication, his guidance is specific. CEOs and CFOs are experienced risk managers who evaluate risk and reward in every decision. What they need from security is an accurate valuation of the organization's cyber exposure, presented as business impact rather than technical terminology. The conversation then turns to the labor market. Jim confirms what many candidates experience: the entry level is saturated, while engineer-level positions remain unfilled. He outlines the practical path into the field, including structured internships modeled on medicine and psychology, a four-year degree completed on employer tuition reimbursement, and AI governance as a second skill. He closes with his position on AI adoption: prohibition fails because employees will use AI regardless, so organizations should provide a sanctioned, secure path, supported by enforced data classification and data loss prevention. A follow-up episode on AI and data governance is planned. Governance as cybersecurity's biggest area of progressNIST 800-53 rev 5, CSF 2.0, and the formalization of governanceSecurity as a business enabler rather than a technology functionHow ransomware changed executive awareness of cyber riskRemote work and the expansion of the security perimeterPresenting cyber risk to boards in business termsWhy security awareness and workforce involvement are staffing necessitiesJim's career path: history degree, campus IT, security leadershipProfessional humility and the role of community in the fieldThe labor market: saturated entry level, unfilled engineer tierInternships, degree requirements, and career progressionAI governance as a career skill and an organizational requirementAI adoption strategy: sanctioned paths instead of prohibitionData classification and DLP as the next area of maturity Jim Mapes is a practicing CISO, advisor, and adjunct professor who has worked in security since the late 1990s, spanning the antivirus and Windows NT era through today's governance-driven, board-level discipline. He entered the field through campus IT work with a history degree, which he credits for the assessment, analysis, writing, and communication skills that carried him into leadership. He teaches in boot camps and university programs, advises organizations on security leadership, and expects the CISO role to eventually report into enterprise risk under a chief risk officer. Jim on LinkedIn: https://www.linkedin.com/in/jimmapes/

  2. Sep 3

    AI Needs Guardrails, Backups Need Testing, and Your New Hire Might Not Exist

    Georgeo Xavier Pulikkathara enlisted in the Army at 18 as a private E1. He's a colonel now, with 15 years at Microsoft behind him, a PhD in cybersecurity in progress at 58, and a job title most security leaders never hold: both CIO and CISO at the same company, managing one budget to ROI and the other to risk. In this conversation, Georgeo and Taylor start with the best bad advice he ever received, that technology is a fad, and why every wave since has proven the deeper point: the technology changes, the need for people who understand the business does not. Georgeo lays out his case for AI with guardrails, from the newborn being asked to do brain surgery to the Workday hiring case that pushed the industry toward open-box AI, and explains why he still trusts a 35-year-old spidey sense over a confident hallucination. Then it gets practical: the four-tier monitoring model that treats endpoints as the last line instead of the first, the North Korean fake worker fraud his team catches through IP checks and shared bank accounts, the breach that lost four terabytes in 40 minutes through an unwatched pipeline, and the military preparation mindset behind his incident response. Dig the foxhole before the fight. Practice containment. Restore the whole application, not one file, and time it. He closes with the three Cs he hires for and why a growth mindset beats any single technical skill. Topics Covered: "Technology is a fad": surviving mainframes, offshoring, cloud, and now AIThe light switch and the electrician: why learning to code still mattersAI as a newborn: training, ethics, guardrails, then agencyHallucinations, the Workday case, and black-box vs open-box AIWearing both hats: managing to ROI as CIO, managing to risk as CISOWhat he reports to the board, in two bucketsThe four tiers: identity, production, business applications, endpointsCatching North Korean fake remote workers: proxies, locations, bank accountsRansomware's migration between industries, and observability on any budgetArmy lessons: preparation, PICERL, containment, and walking backward from the fightTesting backups against real recovery objectivesThe three Cs of hiring: character, competency, commitment Guest Georgeo Xavier Pulikkathara is a CIO and CISO with roughly 35 years across technology and security, including 15 years at Microsoft and early days at Cooper Industries. He is a US Army colonel who began as an enlisted private, came up through the infantry, and carries the military's preparation discipline into incident response, business continuity, and board reporting. He is currently pursuing a PhD in cybersecurity, mentors service members toward their CISSPs, and connects job seekers with roles whenever he can. Georgeo on LinkedIn: Georgeo Xavier Pulikkathara Pull quotes: "They gave birth to a child, and because it's AI, they want their child to do brain surgery tomorrow.""What does it do? It does what people do. It makes stuff up.""We literally discredit the person with 30 years of experience, because AI says it's possible, so you're wrong.""A CIO manages to the ROI. If I'm a CISO, I'm managing to the risk.""You're taking on a risk you don't have to.""You'll have four or five people with the same bank account.""I walk backward from the fight.""Many people make the assumption that they got backups. Have you checked it? Can you restore from it? Have you tried?""Competency, character, commitment. Show me that. That's who I hire."

  3. Aug 20

    From the SEC to 25,000 Board Members: Pricing Cyber Risk Like an Insurer

    Christopher Hetner has seen the board conversation from every seat: building New York City data centers in the nineties, running global information security at GE Capital, advising two chairs of the SEC as senior policy advisor, and three years inside the insurance industry learning how brokers and carriers actually price cyber exposure. Today he is Chief Cyber Advisor at World Wide Technology, Cyber Risk Advisor to the National Association of Corporate Directors and its roughly 25,000 members, and chair of the AI and Cyber Insights Council for the NASDAQ Center for Board Excellence. In this conversation, Chris and Taylor dig into the numbers behind the board disconnect: roughly 70 percent of directors are still not in tune with how cyber and AI materially impact the business, many CISOs get 20 minutes with the audit committee once a year, and AI has compressed attack reconnaissance from months to minutes. Chris lays out the fix layer by layer. Build an enterprise risk management structure even when no regulator requires it, with a charter, a risk register, and the heads of the business in the room. Quantify exposure with annual loss expectancy analysis benchmarked to your peer group, in the same categories the insurance markets use. Then go the step further that traditional models skip: tell the board where to deploy capital, and trend the exposure down quarter over quarter. Also in here: why the CISO should never report to the board alone, the professionalization problem behind slow risk quantification adoption, treating AI agents like employees who commit agent error, and why post-quantum readiness has to start now. If you present to a board, sit on one, or want to someday, this episode is a masterclass. Chris's path: NYC data centers, GE Capital global CISO, senior policy advisor at the SECWhy sophisticated boards still struggle: business lens, not bits and bytesThe 70 percent problem and governing on 20-year-old assumptionsReconnaissance compressed from three or four months to minutesThe isolated CISO: M&A blind spots, inflated budgets, reactive postureBuilding enterprise risk management without a regulatory mandateCharters, risk registers, and the COSO frameworkReporting in tandem with the CFO, chief risk officer, and heads of businessAnnual loss expectancy analysis and the insurance markets as the ultimate arbiterPeer group benchmarks: why pharma, hospitals, and trading platforms all look differentGoing beyond FAIR: substantiating loss and directing capital"A language that we understand": what changes for the boardWhy cyber risk quantification adoption is still low, and the tactical CISO problemCulture and tone from the topAI agents as employees, agent error, and agentic-to-agentic monitoringQ-day and starting post-quantum readiness now Christopher (Cristobal) Hetner is the Chief Cyber Advisor at World Wide Technology, Cyber Risk Advisor to the National Association of Corporate Directors, and chair of the AI and Cyber Insights Council for the NASDAQ Center for Board Excellence. His nearly 30 years in cyber and technology include building data centers in New York City, serving as global CISO at GE Capital, four years as senior policy advisor to two chairs of the SEC, and three years working with major insurance brokers and carriers on sizing cyber exposure. He also advises the Cyber Future Foundation and engages roughly a dozen boards a year as an independent expert. Chris on LinkedIn: Christopher Hetner

  4. Aug 6

    Private Equity Speed, Shadow AI, and the Middle Layer Everyone Skips

    Kevin Lewis has a political science degree, a career that started while he was waiting to hear back from the NYPD, and a job today that puts him inside a stack of companies at once. He is the CISO at E78 Partners, a boutique consulting firm serving small and mid-size private equity funds and their portfolio companies, where he also sits in fractional CIO and CTO seats for clients, most of them in med spa and healthcare. In this conversation, Kevin and Taylor get into why the industry's biggest win is that security stopped being the department of no, how to translate risk for a CFO who has already decided what security should cost, and what private equity's two-day definition of "fast" teaches you about scoping honestly. Kevin walks through the AI reporting pilot that pulled 15 systems into one data lake and replaced a week-long report request with a real-time answer. Then the harder stuff: why he thinks the talent shortage is partly a spending decision, why he does not tolerate gatekeeping on his team, what he actually screens for when he reads every resume himself, and why the network is the middle layer most career-changers skip. He closes with the culture playbook, including the reframe worth stealing: phishing simulation results measure how well the security team communicated, not how bad the employees are. Whether you run a program, advise one, or are trying to break into the industry, this one is full of things you can use on Monday. What's working in security: the shift from "no, you can't" to "let's make this work"Why the seat at the table matters for the information, not the titleSelling to a CFO: the daily cost of zero work, remediation, and reputationSecurity dashboards with business metrics attachedWhat private equity's timeline teaches you about honest scopingThe AI pilot: 15 systems, one data lake, and an agent that builds the KPI reportWhy mentoring faded, and why Kevin requires it from his leadsGatekeeping, the scarcity mindset, and the tools-instead-of-people trapHiring without certification or degree requirementsThe network: the middle layer between "no computer experience" and "security analyst"Why "we're not a target" is the sentence that makes you oneSecurity awareness without fear, and phishing as a metric on your own teamResponsiveness as the real control for shadow IT and shadow AIRetiring a rogue tool without making an enemy Kevin Lewis is the CISO at E78 Partners, a boutique consulting firm that works at the intersection of the CEO, CFO, and CIO for private equity funds and their portfolio companies. Alongside running E78's internal security program, he takes fractional technology leadership roles with client companies and handles pre-close technology due diligence for PE deals. His career spans a DOD contractor, fashion and apparel, and now consulting across whatever industry walks in the door, which suits him: to Kevin, it's all bits and bytes. He holds a master's in cybersecurity and a bachelor's in political science, came up through help desk and networking, and mentors relentlessly because that is how he got in. Kevin on LinkedIn: Kevin LewisEmail: klewis@e78partners.comE78 Partners: e78partners.com

  5. Jul 17

    The Dark Knight of Game Economies on AI, Curiosity, and Guardrails

    Ward Spangenberg has spent his career finding the gaps: mapping trout DNA with a homemade database in college, dismantling a game economy's black market so thoroughly that players nicknamed him the Dark Knight, and helping build the case for bug bounties at HackerOne. Now he's the founder of Behavry.ai, building in the category Gartner calls guardian agents. In this conversation, Ward and Taylor dig into why security spends its money explaining last night instead of preventing tomorrow, what purple teaming should have become, how to hire engineers with the play instinct, and why AI won't take over but ungoverned agents absolutely will hurt you. Ward breaks down the four things real AI agent governance requires: no self-attestation, real-time review of every action, human-in-the-loop escalation instead of binary yes/no decisions, and tamper-evident audit trails that regulators are about to start asking for. Whether you're a practitioner, a founder, an investor, or just AI-curious, this one is full of stories you'll retell. What's acutely broken in security: an industry built on hindsightThinking like an attacker: every door, every window, one unlockedPurple teaming as a quarterly exercise when you don't have the budgetHiring for curiosity: role-play interviews and the "what do you play with at home" questionWhy AI won't take over (and why it doesn't write perfect code)The junior analyst who becomes a level two with the right AI toolingWard's origin stories: trout genetics, game fraud, and the Dark KnightWhy you can't kill the black market: the bug bounty lessonBehavry.ai and the guardian agents category: proxy, policy, attestationThe compliance wave: EU AI rules, Wyoming, and the SECWard Spangenberg is a longtime security practitioner and leader whose career spans companies like Uber, HackerOne, and a Silicon Valley gaming company, plus years presenting to lawyers and law enforcement investigators. He is the founder of Behavry.ai, an AI governance platform that adds policy, human-in-the-loop controls, and independent, tamper-evident attestation to any AI agent, model, or provider. He is also a rugby coach, a gym rat, and the kind of person who stuck a paper clip in an outlet as a kid and grew up to build guardrails for a living. Behavry.aiWard on LinkedIn: Ward SpangenbergWard on Twitter/X: @wardspan

  6. May 28

    Line Cook to CISO: Eric Freeman on AI, Access Control, and Why Security Is Just Dinner Prep

    Eric Freeman is the CISO at Writer, an AI-native company that has built its own large language model. Before that, he worked across blockchain and emerging technology. Before any of that, he was a line cook pulling 16-hour shifts in a restaurant kitchen six days a week. That background shows up in everything about how he leads. In this episode, Eric draws a direct line between prepping for dinner service and implementing security controls, between reading a plate and reading a log, between surviving a Friday night rush and surviving a major incident. We get into how AI is changing both offense and defense in cybersecurity right now, with specific examples of how his team is using LLMs to automate vulnerability validation end-to-end. He explains why context is the only thing that makes AI useful and shares a learning framework where team members use personal analogies to internalize unfamiliar concepts through LLMs. Eric also doesn't hold back on what's broken. He makes the case that cybersecurity stress is a structural problem, not a personal one, and proposes a mandatory security credit score for businesses. He breaks down prompt injection as social engineering for machines, agents as scripts with more dynamicness, and reduces all of cybersecurity to a single mental model: access control. We close with his framework for the three camps of cybersecurity buyers, why two of those camps are the reason the industry still sells on fear, and how to build a security culture with engineers by making the secure path the fastest path. For practitioners, vendors, investors, and anyone trying to understand how the cybersecurity industry actually works underneath the noise. Connect with Eric Freeman on LinkedIn: https://www.linkedin.com/in/eric-m-freeman/

  7. May 14

    Data Governance, Board Buy-In, and the Thing You Can't Shut Off: A CISO's Cross-Industry Playbook

    Janet Heins has led cybersecurity programs in pharma, manufacturing, cruise lines, broadcast media, and healthcare. Every industry felt unique from the inside, and they are. But the patterns she's found underneath are what make this conversation worth listening to. Every industry has a system that can't be shut off, even when security demands it. Every organization has legacy infrastructure that's too embedded to replace and too old to protect with modern tools. And almost no company has a dedicated leader responsible for governing the data that everything else depends on. In this episode, Janet walks through what she's learned moving across industries by design. She shares the four-category framework she uses to get board buy-in for cybersecurity investments: operational, financial, reputational, and regulatory. She explains why aligning security to the company's mission is the difference between being seen as the department that says no and being treated as a strategic partner. And she gets into why data governance is the gap that's making every other cybersecurity and AI challenge harder than it needs to be. We also talk about AI and what it means for practitioners right now, why university cybersecurity curricula are struggling to keep pace, what major security incidents actually feel like from the inside, and what Janet learned writing her book Go Ahead, Ask For It about making your value visible and advancing your career. This one is for CISOs who want a framework they can use in any industry, practitioners thinking about career growth, vendors who want to understand how security leaders actually make decisions, and investors trying to evaluate security maturity from the outside. Connect with Janet Heins on LinkedIn: https://www.linkedin.com/in/janetheins/ Get Go Ahead, Ask For It on Amazon: https://www.amazon.com/Go-Ahead-Ask-Value-Undeniable-ebook/dp/B0GLR2W4D5

Ratings & Reviews

About

The Cybersecurity Ecosystem Show connects the full spectrum of the industry: practitioners, investors, vendors, regulators, and everyone in between — because the more we learn from each other, the stronger we become.