The Professional CISO

David Malicoat

Shaping Cybersecurity Leadership: Today, Tomorrow, Together.

  1. 10 DE SET.

    Responsible AI or Responsible Marketing? A CISO’s Take

    "I get it. I need to stop banging on the table. This will be fixed in future episodes. Sorry for the poor sound experience." - David   Get your Responsible AI Vendor Due Diligence Checklist here: https://webforms.pipedrive.com/f/ccV6a7kFIWKZpodmLcDbBhKhYnVU5N81A2tM20DGC8gepc0UtzfcqYaHXfzBi8gzuz   Episode Summary: In this episode of The Professional CISO Show, David Malicoat explores whether “Responsible AI” pledges from vendors are genuine safeguards or simply marketing buzz. Using Zscaler’s recent claims as a case study, David walks through vendor promises, compliance implications, audit gaps, and blind spots around explainability, bias, and portability.   The episode introduces a practical CISO Vendor AI Evaluation Sheet across six domains — data handling, AI governance, auditability, liability, transparency, and exit strategy — to help CISOs push beyond assurances and demand evidence.   Key Takeaways: Why “Responsible AI” is often indistinguishable from “Responsible Marketing”The compliance challenges with GDPR, HIPAA, CCPA, SR 11-7, and the EU AI ActHow metadata, audit evidence gaps, and third-party dependencies introduce hidden riskWhy boards must be educated on AI risk vs. AI marketing hypeWhy CISOs must own the Responsible AI conversation before regulators step inNotable Quotes: “Responsible AI should be more than a press release. It must be auditable, enforceable, and defensible in front of a regulator.”“When regulators knock, they won’t call the vendor first. They’ll call you.”“Don’t just take a vendor’s word for it — ask hard questions, demand evidence, and get it in writing.”Listener Benefits: By listening, you’ll gain a sharper lens for evaluating AI vendor claims, practical tools to strengthen your vendor management process, and strategies to get ahead of inevitable regulation.   Call to Action: 👉 Download the free CISO Vendor AI Evaluation Sheet from the show notes. 👉 Share this episode with your peers and comment your perspective on LinkedIn. 👉 Subscribe on Spotify, Apple Podcasts, and YouTube. 🔖 Hashtags #ResponsibleAI #CISO #CybersecurityLeadership #TheProfessionalCISO #AICompliance #VendorRisk #AIGovernance

    48min
  2. 20 DE AGO.

    AI Adoption vs. Security Reality — Insights from GPSEC STL

    Sponsors: ObservoAI (www.observo.ai) Guidepoint Security (www.guidepointsecurity.com)   Episode Summary: AI isn’t just hype anymore — it’s transforming the way enterprises operate. At GPSEC St. Louis, David Malicoat sits down with Felix Simmons, Principal Security Architect at GuidePoint Security, to cut through the noise around AI adoption, risk, and controls.   Felix explains why AI is unlike past technology waves, how business demand is driving adoption faster than security teams can keep up, and what enterprises can do to prepare. From agentic AI and non-human identities to offline models and emerging security tooling, this conversation offers a practical guide for CISOs navigating AI in the enterprise.   What You’ll Learn in This Episode: The real risks of AI adoption beyond the hypeHow business-driven demand changes the security equationWhy AI controls lag adoption — and what to do about itThe rise of agentic AI and new identity risksOffline models, adversarial risks, and scanning challengesWhat the future of AI-driven enterprise security may look like Guest: Felix Simmons — Principal Security Architect, GuidePoint Security   Links & Resources: 🌐 Website: www.thpc.co📺 Watch More Episodes: http://www.youtube.com/@TheProfessionalCISO 🎧 Listen on https://open.spotify.com/show/2C7JojNZPdg1g6AXvpKDfn?si=a7ac3172bb414673 🍏 Listen on https://podcasts.apple.com/us/podcast/the-professional-ciso/id1731138021 💼 Connect on https://www.linkedin.com/company/the-professional-ciso-show  Hashtags: #Cybersecurity #CISO #AI #EnterpriseSecurity #GPSEC #GuidePointSecurity #ObservoAI

    17min
  3. 13 DE AGO.

    EP82: Lessons from CISO XC DFW: Leadership, Risk & Real-World Security

    Summary: Recorded live at CISO XC DFW, this episode of The Professional CISO Show features three powerful conversations from leaders shaping the future of cybersecurity.   First, Sonya Wickel shares her 24-year career journey from IT generalist to CISO & CIO, offering insights on fourth-party risk, the value of empathy in leadership, and the importance of staying sharp in both IT and cybersecurity.   Then, Eric Bowerman takes us inside the complex task of securing Dallas Fort Worth International Airport — from operational technology and stakeholder management to implementing passwordless authentication and preparing for global events like FIFA.   Finally, Tera Davis explains how CyberOne has built a true community partnership with CISO XC, scaling professional services, preparing organizations for AI adoption, and fostering the next generation of security talent. Sponsors Valence Security (www.valencesecurity.com) CISO XC (www.cisoxc.com)   Key Topics Covered: CISO/CIO dual-role challenges & strategiesThird & fourth-party risk management best practicesCritical infrastructure & OT security challengesBuilding trust and stakeholder alignment in high-impact environmentsPasswordless authentication for operational teamsAuthentic sponsor–community relationshipsScaling professional services & AI readiness Links & Resources: 🌐 Website: www.thpc.co 📺 Watch More Episodes:  http://www.youtube.com/@TheProfessionalCISO 🎧 Listen on Spotify: Open on Spotify 🍏 Listen on Apple Podcasts: Open on Apple Podcasts 💼 LinkedIn: Follow on LinkedIn Hashtags: #CyberSecurity #CISO #TheProfessionalCISO #CISOXC #CyberLeadership #RiskManagement #OTSecurity #ThirdPartyRisk #AirportSecurity #Passwordless #CyberCommunity #CyberOne #ValenceSecurity

    38min
  4. 6 DE AGO.

    From Data Governance to AI Security: Kristi Cook on Building Resilient Teams

    Sponsors AIM Security (www.aim.security) Guidepoint Security (www.guidepointsecurity.com)   Kristi Cook, Head of Cybersecurity at Peabody Energy, joins David Malicoat live from GPSEC St. Louis — with AIM Security as our midday sponsor — to discuss how she’s leading her team through AI adoption, data governance, and talent development. From leveraging conferences as both morale boosters and strategic accelerators, to building a sustainable talent pipeline through the CyberUp apprenticeship program, Kristi offers actionable insights for CISOs facing rapid technological change.   We also dive into the unique trust and collaboration in the St. Louis cybersecurity community, and why AI may finally give security leaders the leverage to fix long-standing data governance challenges.   Key Topics Covered: Leadership panel insights: AI, SaaS security, hiring, and retentionUsing conferences for team building and strategy alignmentJustifying training investments to executive leadershipFoundations for AI security: IAM and data protectionSolving the talent gap with apprenticeship programsWhy local community trust matters in cybersecurityPreparing for the next wave of rapid tech change  Resources & Links: AIM Security: www.aimsecurity.aiCyberUp Apprenticeship Program: wecyberup.orgThe Professional CISO Show Website: www.thpc.coWatch on YouTube: @TheProfessionalCISOListen on Spotify: Click HereListen on Apple Podcasts: Click HereConnect on LinkedIn: The Professional CISO Show  #️⃣ Hashtags #Cybersecurity #CISO #TheProfessionalCISOShow #DataGovernance #AIsecurity #Leadership #TeamBuilding #CyberTalent #IdentityAccessManagement #StLouisCybersecurity #GPSEC #PeabodyEnergy #CyberUp

    15min
  5. 29 DE JUL.

    CISO XC Live: Conversations on Innovation and Threats

    Sponsored by HivePro (www.hivepro.com) and CISO XC (www.cisoxc.com). EP80 – CISO XC DFW | Hive Pro Special: AI, Identity & The Future of Cyber Roles   Live from CISO XC DFW, The Professional CISO Show dives into the intersection of innovation, leadership, and cyber resilience. Host David Malicoat sits down with: Ted Sanders, BISO and cybersecurity educator, to discuss embedding cyber strategy at scale and why the BISO role is the next great proving ground for future CISOs.Jon Brickey, SVP & Cybersecurity Evangelist at Mastercard, as he unpacks his unique career journey from NSA to Mastercard and explains how cyber innovation, threatcasting, and AI will reshape the landscape.Travis Farral, CISO at RK Energy, who shares actionable insights on session token hijacking, third-party risks, and his strategic push for FIDO2 adoption in a hybrid environment.Sponsored by Hive Pro, a leader in Continuous Threat Exposure Management. Learn more at  https://hivepro.com   Key Takeaways: The BISO role as a critical extension of CISO leadershipWhy threat translation is a core skill for cyber leadersHow AI will augment, not replace, cybersecurity rolesJon Brickey’s “Forrest Gump” career across the evolution of cyber defenseIdentity strategy as a cornerstone of modern resilience🎯 Perfect for: CISOs, aspiring cyber leaders, SOC managers, and innovators thinking about the future of security and strategy. 🔗 Links & CTAs 🌐 Website: www.thpc.co 📺 Watch More Episodes: YouTube 🎧 Listen on Spotify | Apple Podcasts 🔗 Follow us on LinkedIn 👤 Guest Info Ted Sanders – BISO in financial services, Cybersecurity Instructor at Collin CollegeJon Brickey – SVP & Cybersecurity Evangelist, MastercardTravis Farral – CISO, RK Energy📌 Related Episodes EP79: Rob T. Lee on Cybersecurity Training FuturesEP77: The AI Opportunity for CISOs🔖 Hashtags #Cybersecurity #CISO #BISO #AIinSecurity #CyberInnovation #MastercardSecurity #FIDO2 #ThreatExposure #HivePro #TheProfessionalCISO #CISOStrategy #CyberEvangelism #CyberLeadership #CyberPodcast

    31min
  6. 23 DE JUL.

    From DFIR Godfather to AI Risk Advocate: Rob T. Lee on Cybersecurity’s Crossroads | RSA 2025

    In this special RSA Conference edition of The Professional CISO Show, host David Malicoat sits down with Rob T. Lee—Chief of Research at SANS Institute and a foundational figure in cybersecurity. With nearly three decades of experience spanning the Air Force, Mandiant, and SANS, Rob shares his insights on the evolving challenges of the CISO role, the toxicity of today’s security environments, and the urgent need for AI literacy across the industry. Rob dives deep into the accelerating threat landscape, the need for cyber safe harbors, and why he believes we’re on the verge of normalizing breaches as the cost of doing business. He also makes the case for rewarding defenders and rethinking how we define cybersecurity success. Key Highlights: Why most CISOs say “never again”—and what needs to changeWhy Rob coined DFIR and CTI (and the story behind it)The CISO “zero-sum game” and how toxic cultures persistRob’s 4-part personal health mantra: Sleep, Diet, Exercise… and AIA call to “Learn AI daily”—for security pros and business leaders alikeWhat boards should be doing—and why every board needs a cyber voiceRob’s RSA keynote preview: cyber safe harbors and AI velocity imbalanceGuest: 👤 Rob T. Lee – Chief of Research, SANS Institute 🔗 https://www.sans.org/profiles/rob-t-lee/ Host: 🎙️ David Malicoat, The Professional CISO Show 🌐 www.thpc.co Listen & Subscribe: 🔊 Spotify: The Professional CISO Show on Spotify 🍎 Apple Podcasts: The Professional CISO Show on Apple 📣 Hashtags: #Cybersecurity #TheProfessionalCISO #RSA2025 #RobTLee #SANS #DFIR #AIinSecurity #CyberRisk #CISOLeadership #CTI #CyberSafeHarbor #LearnAIDaily #IncidentResponse #AIThreats #CyberCulture

    48min
  7. 14 DE JUL.

    🎙 Episode 77 – CISO XC DFW 4: Securing the Real World

    🔹 Live from CISO XC DFW (www.cisoxc.com) | Sponsored by Valence Security (www.valencesecurity.com) In this field-recorded episode of The Professional CISO Show, host David Malicoat returns to CISO XC DFW for another round of dynamic, on-the-ground conversations with three influential cybersecurity leaders — each offering a unique and grounded perspective on today’s real-world risks and tomorrow’s security frontiers. Cyber attorney and governance thought leader Shawn Tuma returns to discuss the resurgence of business email compromise (BEC), the importance of humility in cyber defense, and why AI governance is rapidly becoming a core CISO responsibility. Maritime security executive Glen Vickers walks us through the harsh realities of securing satellite-connected vessels, dealing with Starlink, and the challenges of maritime connectivity. Then, longtime friend of the show and security visionary Chris Cochran reveals his newest venture: Commandant, an AI-powered incident response co-pilot designed to fundamentally change how organizations respond to crisis events — complete with its own assistant, Lucy. Throughout the episode, we also explore the challenges of securing SaaS ecosystems, managing identity at scale, and the rising importance of proactive vendor evaluation and tabletop readiness. Whether you’re a field-hardened CISO or just starting your executive security journey, this episode brings you into the heart of cybersecurity’s most pressing conversations — unfiltered, insightful, and straight from the source. 🔑 What You’ll Learn in This Episode The dangerous re-emergence of BEC as a top threat vector — and why AI may be amplifying the riskWhy CISOs must lead the charge on AI governance and strategy — or risk being sidelinedHow FIDO and identity modernization can reduce exposure to targeted fraudInsights on satellite cybersecurity, Starlink limitations, and maritime network vulnerabilitiesA behind-the-scenes preview of “Commandant,” an AI co-pilot for incident response — designed to help IR teams with note-taking, SLA tracking, notification workflows, and continuous tabletop exercisesHow vendor selection, tabletop simulations, and small supplier coordination can make or break your organization during a crisisWhy humility, not hubris, is the most underrated leadership trait in cybersecurity💬 Notable Quotes “Just because you can’t think of how the attacker got in doesn’t mean they didn’t. That’s why we need more humility in this industry.” —Shawn Tuma“AI isn’t just a buzzword. It’s a once-in-a-generation shift — and CISOs have a chance to shape it from the start.” —David Malicoat“Lucy is designed to help you during your worst day — capturing context, notes, contracts, timelines, and guiding you through the fog of war.” —Chris Cochran“We’re securing vessels in the middle of the ocean using tech that was old when we got it — Starlink’s changed the game, but it’s brought new challenges too.” —Glen Vickers“A $5M cyber insurance policy might only cover $250K of social engineering fraud. The rest is on you.” —Shawn Tuma🎧 Listen & Subscribe 📍 Available now on all major platforms: 🔗 Spotify 🔗 Apple Podcasts 🌐 Full episodes and show resources at www.thpc.co 📣 Stay Connected with The Professional CISO Show 📺 Watch on YouTube 💼 Follow on LinkedIn 🧠 Guest Info Shawn Tuma – Partner at Spencer Fane, co-author of GC + CISO ConnectionGlen Vickers – CISO at ABS WavesightChris Cochran – Co-founder, Commandant AI | Formerly of Netflix, NSA, Mandiant📚 Related Episodes EP 71 – CISO Culture & AI StrategyEP 63 – AI Governance and the Role of the CISOEP 45 – Shawn Tuma on Legal Risk, AI, and Cyber Insurance🔖 Hashtags #CISO #CyberSecurity #TheProfessionalCISOShow #BusinessEmailCompromise #AIinSecurity #IncidentResponse #MaritimeCyber #StarlinkSecurity #ValenceSecurity #CommandantAI #LeadershipInCyber #FIDO #SupplyChainRisk #CyberInsurance #SaaSVisibility #RealWorldSecurity

    34min

Classificações e avaliações

4,3
de 5
10 avaliações

Sobre

Shaping Cybersecurity Leadership: Today, Tomorrow, Together.

Você também pode gostar de