Security You Should Know

CISO Series

What if you could get a no-nonsense look at security solutions in just 15 minutes? Security You Should Know, the latest podcast from the CISO Series, does just that. Hosted by Rich Stroffolino, each episode brings together one security vendor and two security leaders to break down a real-world problem and the solution trying to fix it. Expect straight answers on: How to explain the issue to your CEO What the solution actually does (and doesn't do) How the pricing model works Then, our security leaders ask the tough questions to see what sets this vendor apart. Subscribe now and and stay ahead of the latest security solutions. Visit CISOseries.com for more details. Security You Should Know: Connecting security solutions with security leaders.

  1. 11h ago

    Simplifying MDR for SMBs with ThreatDown

    In this episode, Dean Shroll, senior director of sales engineering at ThreatDown, explains how the company's Nebula and OneView consoles simplify protection across Mac, Linux, and Windows endpoints while its managed detection and response team absorbs the 24/7 monitoring that resource-constrained teams can't staff on their own. Joining him are Jonathan Waldrop, CISO at Acoustic, and Arif Hameed, CISO at C&R Software. Want to know: Why is managing security for resource-constrained organizations suddenly getting more attention? How does ThreatDown keep its console simple without sacrificing depth across Windows, Mac, Linux, and cloud environments? Where does ThreatDown draw the line between what it automates and what still needs a human analyst? How does the platform distinguish suspicious behavior from normal DevOps activity without drowning teams in false positives? What guardrails exist to stop overly broad exclusions from opening up a device? Who owns what when an MDR provider is involved, and where does that responsibility actually end? How should a CISO justify an MDR investment to the board when nothing bad happens? Check out the episode for the answers you need. Huge thanks to our sponsor, ThreatDown ThreatDown delivers elite Managed Detection and Response purpose-built for resource-constrained teams with high-efficacy protection without complexity. Combining artificial intelligence and expert analyst judgment, ThreatDown intercepts sophisticated attacks with speed and accuracy, scaling security effortlessly. Recognized by MRG Effitas, AVLab, and G2, ditch fragmented tools for fast, 24/7 protection without overhead.

  2. Sep 14

    Cloaking the Network from Discovery with AppGate

    In this episode, Leo Taddeo, CEO and President at AppGate, explains how the company's zero trust network access platform cloaks internet-facing infrastructure from discovery, uses direct-routed architecture instead of cloud-routed hairpinning to avoid the latency tax, and layers in continuous, context-aware policy checks that go beyond device posture and MFA. Joining him are Ross Young, co-host of CISO Tradecraft, and Derek Fisher, Director of the Cyber Defense and Information Assurance Program at Temple University. Want to know: Why does securing remote access remain one of the top attack vectors year after year? How does AppGate's direct-routed architecture avoid the latency and throughput limits of cloud-routed competitors? What happens to a user's access when the circumstances that justified it change, like a closed service ticket? How does cloaking network infrastructure stop an adversary's reconnaissance before it starts? What's the fallback when a controller hosted in a customer's own data center goes down? How does AppGate defend against credential replay and man-in-the-middle attacks that bypass MFA entirely? What does AppGate's per-user licensing model mean for organizations managing multiple devices and enclaves? Check out the episode for the answers you need. Huge thanks to our sponsor, AppGate AppGate secures and protects an organization's most valuable assets with its high performance Zero Trust Network Access (ZTNA) solution. AppGate ZTNA is the only direct-routed Zero Trust solution built for peak performance, superior protection and seamless interoperability. AppGate safeguards enterprises and government agencies worldwide. Learn more at appgate.com.

  3. Aug 17

    Securing the AI Control Plane with Speakeasy

    In this episode, Sagar Batchu, CEO of Speakeasy, explains how the Speakeasy AI control plane lets organizations adopt AI everywhere and still prove it's governed — putting every agent, tool, and MCP server behind a single security layer that authenticates each action, enforces policy, and inspects every session for prompt injection and data exfiltration. Pressure-testing the approach are George Finney, CISO at The University of Texas System, and Nick Espinosa, host of The Deep Dive Radio Show. Want to know: Why is knowing what your AI agent can access still an unsolved problem, and how much of it traces back to the identity and data governance we never fixed for humans? Should an AI agent ever be allowed to take an action no individual can fully understand, even when it's statistically more effective than the human alternative? Where's the line between legitimate governance and surveillance, and how do you assure employees you're not building a panopticon? Are there decisions and departments that should stay permanently in human hands, off-limits to agents entirely? When an agent acts through a company's API and something goes wrong, who's actually responsible: the employee, the company, the model developer, the API provider, or the governance platform? Could a control plane have flagged the week's biggest AI incident before it escalated? Is adopting this really as simple as switching on enterprise settings and plugging in an API, whether you're an SMB or the Fortune 1? What is "cognitive surrender," and why does Speakeasy's CEO think it's the one quality companies most need to protect? Check out the episode for the answers you need. A huge thanks to our sponsor, Speakeasy. Speakeasy is the enterprise AI control plane. It governs every AI agent, tool, and MCP server from one place. Every connection is authenticated, every policy enforced, and every agentic action inspected and logged. So organizations can scale AI adoption with visibility and control. Copy for below Banner: AI usage is outgrowing your enterprise controls. Speakeasy is the AI control plane that governs every agent, assistant, and MCP server from one layer. Each connection is authenticated, each policy enforced, and every action recorded. So you stay in control as AI adoption scales."

  4. Aug 4

    Proving Resilience with Gambit Security

    In this episode, Curtis Simpson, CSO at Gambit Security, explains how Gambit moves organizations past that guesswork by continuously mapping a company's minimally viable business capabilities and validating whether the infrastructure, backups, and recovery processes behind them can actually deliver within the timeframes the business requires. Joining him to pressure-test the approach are Howard Holton, former CEO of GigaOm, and Adam Palmer, CISO at First Hawaiian Bank. Want to know: Why do so many disaster recovery plans hold up on paper but fail the moment they're actually needed? What's the real difference between having something backed up and proving you can recover it? What is a "minimally viable company," and how much of mapping it is automated versus built on human input? What happens when your infrastructure fails today, versus what Gambit's roadmap has planned for tomorrow? What should actually land in front of your CEO or board to demonstrate recovery confidence? Is there an organization too small, or too mature, to get value from this kind of resilience assessment? Why does decades-old infrastructure like the mainframe often cause the longest, most damaging outages? Why is now the moment for security to finally move from a "trust but trust" model to "trust but verify" on recoverability? Check out the episode for the answers you need. Huge thanks to our sponsor, Gambit Security Gambit is the AI-native cyber resilience platform for enterprises that can't afford downtime. It continuously maps your live environment, backups, security tools, and infrastructure-as-code, then validates whether your entire stack can actually recover from disruption. Gambit gives security and infrastructure leaders proof of recoverability on demand, so the business keeps running. Balens maps, controls, and proves your recoverability across every layer of your stack - against infrastructure failures, human and AI errors, and cyber threats. One live view of your cloud, IaC, and backups that updates as your environment evolves. Agentless deployment in 15 minutes. Learn more at gambit.security

  5. Jul 20

    Securing the Open Source Supply Chain with ActiveState

    In this episode, Abby Kearns, CEO of ActiveState, explains how her company closes that gap by rebuilding open-source packages from verified sources before they ever reach a developer's pipeline, rather than scanning for problems after the fact. Joining her are Doug Mayer, vp and CISO at WCG, and Howard Holton, former CEO at GigaOM. Want to know: Why is AI increasing exploitability on both the attacker side and the developer side of the open source supply chain? How does a package catalog replace your package manager without slowing developers down or pushing them around the process? What does ActiveState do differently than upstream scanning tools like JFrog Artifactory or Sonatype Nexus? What happens when a developer needs a package that isn't in the catalog yet? How is ActiveState thinking about shadow AI and SBOM coverage beyond language libraries? What upcoming regulatory deadlines, like the EU Cyber Resilience Act, should security teams have on their radar? What happens to open source security when AI produces more CVEs and patches than the maintainers behind these projects can process? Huge thanks to our sponsor, ActiveState ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time.  Curate a private, vetted repository of open source components from the ActiveState Library that developers use safely without scouring the internet. A Curated Catalog provides your security team total control over what enters their environments while giving engineering teams a fast, secure way to build, onboard, and start new projects.

  6. Jun 15

    Elevating the SOC with Prophet Security

    In this episode, Grant Oviatt, vp of product and co-founder at Prophet Security, explains how his platform deploys AI agents to investigate and respond to alerts the way a skilled analyst would, using REST API integrations across existing security tools rather than absorbing all your data into another SIEM. Joining him are Will Gregorian, CISO at Galileo Medical, and Howard Holton, CEO at GigaOm. Want to know: Why are AI-powered SOC tools adding to analyst frustration rather than reducing it? When an AI agent makes a bad call on an investigation, who actually owns that failure? How does Prophet Security's audit trail let you trace every query, piece of evidence, and reasoning step an agent used? Why is Prophet Security using frontier models rather than training its own, and how does security-specific context change the outcome? What does giving an AI agent remediation authority look like in practice, and where does Prophet Security draw the line? How long does it realistically take to go from contract to running Prophet Security against live alerts? Check out the episode for the answers you need. Huge thanks to our episode sponser, Prophet Security Prophet AI is an Agentic AI SOC Platform that investigates and responds with context, shows its reasoning, and elevates every part of your SOC. Prophet AI SOC Analyst investigates and responds to alerts in minutes; Threat Hunter streamlines threat hunts with a natural language interface; and Detection Advisor provides insights on detection quality and coverage.

Ratings & Reviews

4.3
out of 5
9 Ratings

About

What if you could get a no-nonsense look at security solutions in just 15 minutes? Security You Should Know, the latest podcast from the CISO Series, does just that. Hosted by Rich Stroffolino, each episode brings together one security vendor and two security leaders to break down a real-world problem and the solution trying to fix it. Expect straight answers on: How to explain the issue to your CEO What the solution actually does (and doesn't do) How the pricing model works Then, our security leaders ask the tough questions to see what sets this vendor apart. Subscribe now and and stay ahead of the latest security solutions. Visit CISOseries.com for more details. Security You Should Know: Connecting security solutions with security leaders.

You Might Also Like