The cyber weekly

Deogratius Okello, Josephine Olok and Angella Nabbanja

Dive into the world of cybersecurity, book reviews, and effective management strategies, including how to communicate with a board. If this piques your interest, join the club!

  1. Sep 24

    From Fixing Printers to CISO: Grant Hughes' Unlikely Cybersecurity Journey

    Ever feel stuck in a help desk role, wondering if cybersecurity is even reachable without a degree or years of "experience"? Grant Hughes was exactly there โ€” until he sent one cold email that changed his career forever. In this episode of The Cyber Weekly Podcast, Grant Hughes (CISO at The Nascent Group, Founding President of the ISC2 Cape Town Chapter) breaks down: How he went from desktop support to CISO with zero security certs The exact conversation that got him his first break in security Why most security awareness training fails โ€” and what actually works The real reason you don't need 5 years of experience to break in The one skill every newcomer needs right now ๐Ÿ”— Connect with Grant Hughes: Portfolio: https://granthughes.co.za/ LinkedIn: https://www.linkedin.com/in/grant-hughes-52196569/ YouTube: https://www.youtube.com/@granthughes4989 ๐ŸŒ African Tech Talent Support Project: https://isc2capetownchapter.com/africa-tech-talent-support-project/ ๐Ÿข ISC2 Cape Town Chapter: https://www.linkedin.com/company/isc2-cape-town-chapter/ ๐Ÿ’ผ The Nascent Group: https://nascent.group/  LinkedIn: https://www.linkedin.com/company/nascent-group-global/ Chapters 00:53  Meet Grant Hughes: From help desk to CISO 02:05  The one takeaway Grant wants you to leave with 03:12  What pulled him from IT support into cybersecurity 04:56  The cold email that changed his life 08:39  What 6 years on the front lines taught him 10:40  Why the basics keep evolving 11:26  What security culture really means 16:44  Handling employee pushback and busy schedules 19:34  Why explaining "why" makes training stick (the password story) 20:15  No certs, no experience? Here's your path in 24:11  The power of networking (and why it beats applying blind) 26:14  AI, soft skills, and what's next for cybersecurity 30:00  Where to find Grant + the African Tech Talent Support Project

  2. Sep 16

    Why Most CISOs Don't Know What Their Business Actually Does

    ๐Ÿšจ Most CISOs can explain every control on their stack but ask them what the business actually sells, and they go quiet. In this episode of The Cyber Weekly, Deo sits down with Jake Bernardes CISO at Gambit Security, ex-pen tester, chartered accountant, and a guy who learned Chinese and German before ever touching cybersecurity. We get into: ๐Ÿ’ฐ The "Minimum Viable Business" framework for justifying security spend ๐Ÿงฉ Why GRC is broken (and how to fix the forgotten "R") ๐Ÿค– Which security roles AI will kill and which ones it can't touch ๐Ÿ“œ Why Jake thinks certifications are mostly pointless ๐ŸŒ Why your network matters more than your CISSP ๐ŸŽ™๏ธ Building leadership on transparency, vulnerability, and authenticity   Here the links Random Access Memories: https://randomaccessmemories.io Jake Bernardes on LinkedIn: https://www.linkedin.com/in/jakeleobernardes/ Random Access Memories on YouTube: https://www.youtube.com/@RandomAccessMemoriesPod   If you're in GRC, trying to break into cybersecurity, or leading a security team through the AI shift this conversation will change how you think about your career. 00:00 Intro: The Intersection of Chinese & Cybersecurity 01:19 Who is Jake Bernardes? 03:18 How Accounting Creates Better CISOs 04:14 The "Minimum Viable Business" & Proving ROI 08:26 Why GRC is Broken (And How to Fix It) 13:02 The Future of GRC Engineering & Automation 17:32 Why Cyber Certifications Are "Pointless" 19:24 AI is Killing Tier 1 SOC Jobs: What to do next 22:43 The 3 Pillars of True Leadership #TheCyberWeekly #CISO #Cybersecurity #GRC #RiskManagement #CyberCareers #InfoSec #CyberLeadership ๐Ÿ”๐ŸŽ™๏ธ๐Ÿ“ˆ

  3. Sep 2

    Heather Reed - She Turned 5 Volunteers Into 75 Cybersecurity Ambassadors ๐Ÿ”

    Only 40% of her company completed the annual security awareness training. Human error was the #1 risk on the register. So she stopped writing policies and started recruiting people. ๐Ÿ‘ฅ In this episode of The Cyber Weekly Podcast, Deo Okello sits down with Heather Reed โ€” cybersecurity leader, Cyber Security Woman of the Year finalist, competitive cookie designer ๐Ÿช and former Cookie Wars contestant on the Food Network. Heather came into security from marketing, people leadership and compliance, and she says that non-traditional path became her biggest advantage. She never carried the "Department of No" reputation, because she'd spent years on the other side of it. We get into: ๐Ÿ”น How she built a cybersecurity ambassador network from 5 departments to 75 ambassadors โ€” and hit 100% training completion ๐Ÿ”น Why she chose the friendliest people in the business, not the most technical ๐Ÿ”น The 4 years it took to bring 23 factories and 8,000 employees into the ISMS โ€” and how they scored their best audit ever ๐Ÿ”น What a real "yes, if" conversation sounds like when the business wants speed ๐Ÿ”น Tabletop exercises that actually work (hint: ask your execs what keeps them up at night) ๐Ÿ”น Handling DLP and insider risk without turning security into the police ๐Ÿš” ๐Ÿ”น AI agents, guardrails, and why security leaders should be talking to startups ๐Ÿ”น Her honest answer to "did you ever feel you didn't belong?" โ€” and why that question is only ever asked of women ๐Ÿ”น Three things any security leader can do in the next 90 days to shift culture

  4. Aug 20

    90 days from technical to IT risk professional

    โš ๏ธ One overlooked technical issue could become a major financial, operational or reputational crisis. But what exactly is IT risk, and why do organizations invest so much in managing it? In this episode of The Cyber Weekly Podcast, Deo Okello sits down with IT risk and security professional Peter Muhumuza to break down IT risk in practical, easy-to-understand language. You will learn: ๐Ÿ” How technical weaknesses become business risks ๐Ÿ“Š How organizations classify and track risks โš–๏ธ Which risks can be accepted and which require immediate action ๐Ÿš€ How risk professionals support innovation without becoming โ€œMr. Noโ€ ๐Ÿค Why third-party and vendor risk assessments matter โ˜๏ธ The risks created by cloud concentration and AI adoption โœ… Why passing an audit does not mean risk management is complete ๐Ÿ“ˆ How technical professionals can begin transitioning into IT risk within 90 days Peter also explains why effective IT risk management is about more than fixing technical problems. It requires understanding business priorities, regulatory obligations, operational downtime and financial exposure. If you work in cybersecurity, IT, banking, fintech, audit, governance or risk management, this conversation is for you. ๐Ÿ‘ Like this episode ๐Ÿ’ฌ Share your biggest IT risk lesson in the comments ๐Ÿ”” Subscribe to The Cyber Weekly Podcast for more practical cybersecurity conversations ๐Ÿ“ค Share this episode with someone interested in IT risk #TheCyberWeekly #ITRisk #RiskManagement #Cybersecurity #InformationSecurity #GRC #ThirdPartyRisk #CloudSecurity #CyberRisk #ITGovernance

  5. Jul 29

    The Unexpected Risks of Cloud Security That Experts Are Overlooking

    Cybersecurity in the Cloud: The Hidden Threats and Future of Digital Defense If youโ€™re managing cloud infrastructure or responsible for cybersecurity in a hybrid environment, overlooking emerging threats can leave your organization exposed before you even notice the gap. In this episode, Muhiire Bill, a seasoned IT security professional with nearly a decade in financial institutions, reveals the cloud security blind spots most teams miss. From misconfigured cloud resources and weak access controls to API vulnerabilities and social media reconnaissance, this conversation uncovers the real risks hiding behind โ€œsecureโ€ systems. Bill also breaks down how organizations can balance usability, compliance, and protection without slowing the business down.  Youโ€™ll learn: Why misconfigured cloud settings create massive breach risks How multi-factor authentication and role-based access can strengthen defenses Why API security is becoming one of the biggest threats in cloud environments How continuous compliance helps teams stay ahead of attackers Practical ways to align security with real-world operations If you work in IT, security, cloud operations, or leadership, this episode gives you the insight you need to avoid common mistakes and build a stronger security culture. Billโ€™s experience across financial and manufacturing sectors brings a practical, real-world perspective to one of todayโ€™s most important tech conversations. Stay ahead of the curve hit play now.

About

Dive into the world of cybersecurity, book reviews, and effective management strategies, including how to communicate with a board. If this piques your interest, join the club!