Cyber Smokehouse

TBDCyber

This is Cyber Smokehouse. Join Ernie and Graeme as they grill the minds, dig into the experience, and serve up the stories of leaders in cybersecurity. Cyber Smokehouse is sponsored by TBDCyber, a cybersecurity strategy consulting firm.

Episodes

  1. Leading Through Cyber Complexity - Wade Myers - Cyber Smokehouse - Episode # [004]

    5D AGO

    Leading Through Cyber Complexity - Wade Myers - Cyber Smokehouse - Episode # [004]

    In this episode of Cyber Smokehouse, hosts Ernie and Graeme sit down with Wade Myers to explore the leadership discipline required to navigate modern cyber risk. Wade shares why complexity is the enemy of effective security programs, how executives must think about tradeoffs instead of perfection, and why clarity, not control, is the real advantage in today’s threat landscape. The conversation dives into decision-making under uncertainty, aligning cybersecurity with business priorities, and the importance of building teams that can operate confidently in high pressure environments. Wade unpacks how security leaders can move beyond compliance thinking and instead focus on meaningful risk management that strengthens resilience across the organization.   Takeaways: Cybersecurity is a decision-making discipline, not a toolset. Effective programs are built on sound judgment, prioritization, and alignment with business objectives—not simply the deployment of more technology.Risk cannot be eliminated, only managed intelligently. Leaders must move away from the illusion of total control and instead build frameworks that allow them to evaluate tradeoffs clearly and respond with confidence.Complexity is the hidden threat. Overly layered controls, unclear ownership, and bloated processes create blind spots. Simplification improves visibility, accountability, and response speed.Clarity at the executive level determines program success. When leadership understands what matters most, resources are deployed strategically instead of reactively.Security must support business velocity. The strongest programs protect critical assets while enabling innovation and operational momentum.Resilience outperforms perfection. Organizations that plan for disruption, rehearse response, and empower teams to act decisively outperform those chasing zero incidents.Culture shapes security outcomes. Clear communication, ownership, and psychological safety allow teams to raise risks early and act before issues escalate. Quote of the Show: “Cybersecurity isn’t about eliminating risk, it’s about making intelligent decisions under uncertainty.” Links: LinkedIn: https://www.linkedin.com/in/wade-myers-b287833/Website: https://www.equifax.com/ Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550

    45 min
  2. Cyber Resilience in the Real World - Damian Apone - Cyber Smokehouse - Episode # [003]

    FEB 17

    Cyber Resilience in the Real World - Damian Apone - Cyber Smokehouse - Episode # [003]

    In this episode of Cyber Smokehouse, hosts Ernie and Graeme sit down with Damian Apone, cybersecurity executive and practitioner with deep experience building and operating security programs inside complex organizations. Damian brings a grounded, real-world perspective on why cybersecurity initiatives often fail, not because of missing tools, but because of misalignment between people, process, and technology. He shares hard-earned lessons on operationalizing cyber resilience, managing risk in imperfect environments, and helping leaders move beyond checkbox compliance toward security programs that actually work in practice. The conversation covers executive communication, prioritization, realistic threat modeling, and why resilience, not perfection, is the goal.   Takeaways: Cybersecurity failures rarely stem from missing tools. Most breakdowns occur in the handoffs between people, processes, and technology where ownership is unclear and assumptions go unchallenged.Resilience matters more than perfection. Effective security programs assume disruptions will happen and focus on detection, response, and recovery rather than trying to prevent every possible incident.Security must function in real-world conditions. Controls and processes should reflect how teams actually work under pressure, not how frameworks assume they operate in ideal scenarios.Prioritization is essential to managing risk. Organizations must clearly define which assets and threats matter most to avoid spreading security efforts too thin.Executive understanding drives program success. When leaders grasp tradeoffs and business impacts, security initiatives are more likely to be funded, supported, and followed.Compliance is a baseline, not a strategy. Checking boxes may satisfy auditors, but it does not guarantee resilience or meaningful risk reduction.Cyber programs must continuously evolve. Threats, technology, and business priorities change, security strategies must adapt accordingly to remain effective. Quote of the Show: “Resilience isn’t about preventing every failure; it’s about being ready when failure happens.” Links: LinkedIn: https://www.linkedin.com/in/damian-apone-csm-mba-pmp-a45a97/Website: http://genpt.com Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550

    49 min
  3. Preparing for the Quantum Cyber Shift - Gregg Barrow  - Cyber Smokehouse - Episode # 002

    FEB 10

    Preparing for the Quantum Cyber Shift - Gregg Barrow - Cyber Smokehouse - Episode # 002

    In this episode of Cyber Smokehouse, hosts Ernie and Graeme sit down with Gregg Barrow, a global cybersecurity leader at the forefront of quantum-safe computing, to explore one of the most underestimated threats facing organizations today: the coming impact of quantum computing on data security. The conversation dives into crypto-agility, inventorying cryptographic assets, leadership accountability, and the real risks of waiting too long. This episode challenges cybersecurity leaders to rethink long-term resilience in a world where yesterday’s “secure enough” quickly becomes tomorrow’s breach.  Takeaways: Quantum computing poses a real, future threat to today’s encryption standards.Organizations must begin preparing now, not when quantum computers become mainstream.Crypto-agility, the ability to swap cryptographic algorithms quickly, is critical.Most companies don’t know where or how cryptography is embedded across their systems.Inventorying cryptographic assets is the first actionable step toward quantum readiness.Leadership must treat quantum security as a business risk, not just a technical one.Waiting for regulation or vendor mandates may leave organizations dangerously exposed.Quote of the Show: “Quantum computing is already here in pieces, and the implications for security are not as far away as people think.” Links: LinkedIn: https://www.linkedin.com/in/greggbarrow/Website: http://www.ibm.com Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550

    34 min
  4. Data Driven Cybersecurity Decisions - Erik Hart - Cyber Smokehouse - Episode #001

    FEB 3

    Data Driven Cybersecurity Decisions - Erik Hart - Cyber Smokehouse - Episode #001

    How can organizations cut through security tool sprawl and focus on what truly reduces cyber risk? Today’s guest is a veteran cybersecurity leader with more than 25 years of experience helping global enterprises protect their data and operations. Introducing Erik Hart, Chief Information Security Officer at Cushman & Wakefield and former security leader at organizations including CrowdStrike and Mimecast. Erik joins the show to discuss why vulnerability management must become more data-driven, how identity has emerged as the new firewall, and where AI and automation can meaningfully reduce risk. He also shares leadership insights on challenging outdated security practices, prioritizing what matters most to the business, and building security programs that scale with modern, cloud-first organizations. Takeaways: Platform consolidation must be intentional. Moving toward “platformization” can simplify operations, but only if organizations clearly understand which capabilities add real value.Vulnerability management is a data problem, not a scanning problem. Fewer than 10% of vulnerabilities are actively exploited, making prioritization and business context essential.Risk-based decisions beat severity scores. A lower-scored vulnerability exposed to the internet may pose more real risk than a higher-scored internal issue.Security is increasingly driven by analytics. Combining telemetry from tools like EDR, email security, identity platforms, and threat intelligence provides a clearer, more actionable risk picture.Identity is the new firewall. In a SaaS-first, remote-enabled world, strong identity controls matter more than traditional perimeter defenses.Leadership requires responsiveness and trust. Eric emphasizes being accessible, empowering teams to run with ideas, and challenging outdated norms.Business literacy is critical for security leaders. Understanding finance, budgeting, and risk quantification is essential to gaining executive buy-in and long-term funding.Quote of the Show: “I’ve never worked in an organization where there was no risk. Cybersecurity is about understanding which risks actually matter to the business”. - Erik Hart Links: LinkedIn: https://www.linkedin.com/in/emhart1/ Company website: https://www.cushmanwakefield.com/en  Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 YouTube: https://www.youtube.com/@CyberSmokehouse

    44 min

About

This is Cyber Smokehouse. Join Ernie and Graeme as they grill the minds, dig into the experience, and serve up the stories of leaders in cybersecurity. Cyber Smokehouse is sponsored by TBDCyber, a cybersecurity strategy consulting firm.