CISO Tradecraft®

G Mark Hardy & Ross Young

You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level. © Copyright 2025, National Security Corporation. All Rights Reserved

  1. 2d ago

    Claude Code Is INSANE, But Is It Safe? - #299

    Claude Code Is INSANE… But Is It Safe? AI coding just went from “autocomplete my code” to “give me the entire repository and let me run the company.” In this episode of CISO Tradecraft, G Mark Hardy and Ross Young break down what Claude Code can actually do, and the security implications that come with it. Claude Code can read entire codebases, create and edit multiple files, run commands, execute tests, and operate like an AI developer sitting directly inside your environment. But there’s a catch… Every token costs money. And every permission creates risk. We break down: 🔥 Tokenomics — How to get dramatically more AI coding for your dollar 🔥 PRDs — Why you should use powerful models to THINK before cheaper models BUILD 🔥 Security Risks — What happens when an AI agent can execute commands and modify your environment? 🔥 AI Licenses — Individual vs. enterprise and what CISOs need to worry about 🔥 Privacy & Regulated Data — When you may need offline or open-weight models 🔥 Harnesses — The policy-driven guardrails that can move security WAY earlier in the development process 🔥 MCP — How AI agents can connect to tools, systems, and data… and why permissions become a massive security issue 🔥 Agents & Skills — Serial vs. parallel agents, prompts, context, commands, hooks, and Markdown-based skills 🔥 Threat Modeling AI — Why you need to start threat modeling the prompts AND the toolsThe big question isn't: “Can AI write code?” It absolutely can. The question is: “What happens when we give AI the keys to the kingdom?” If you're a CISO, security leader, developer, or anyone trying to understand where agentic AI coding is heading, this episode is for you. 🎙️ Subscribe to CISO Tradecraft for more unfiltered conversations about cybersecurity, AI, leadership, and the future of the CISO. Check out the Harness that Ross is building: https://github.com/Clear-Capabilities/agentic-security

    Claude Code Is INSANE, But Is It Safe? - #299
  2. Aug 25

    VCISO Tradecraft | Carlota Sage - #298

    Most cybersecurity advice is built for massive enterprises. But what happens when you're a small or medium-sized business and you don't have a 200-person security team… or a massive budget? In this episode, Mark Hardy sits down with vCISO Carlota Sage to break down what actually works. Carlota shares lessons from her time at FireEye during its explosive growth and the Mandiant acquisition—and why being a great security leader isn't just about knowing cybersecurity. It's about IT fundamentals. Influence. Emotional intelligence. And knowing how to lead people. We also dive into: Why simply saying "thank you" can transform your security culture 💰 How cybersecurity can become sales enablement and revenue protection 📈 Why security teams should work directly with sales and finance 🔒 Why compliance isn't security—but ISO 27001 and PCI DSS can still be incredibly valuable for smaller companies 🤖 How AI is creating a massive new attack surface 🕵️ The growing risk of sensitive data leaking into AI tools 💸 Why the real cost of AI isn't just the subscription price 🎯 Who should be accountable when AI goes wrong The BIG takeaway? You don't need to be a Fortune 500 company to build a strong security program. But you do need to understand the business, influence people, protect revenue, and help your organization use technology without creating a disaster in the process. Watch now and let us know in the comments: What's the biggest cybersecurity challenge facing small and medium-sized businesses right now? 👇

    VCISO Tradecraft | Carlota Sage - #298
  3. Aug 10

    AI Is Breaking Out and Cybersecurity Isn’t Ready | John Strand - #296

    What happens when AI stops behaving like a tool, and starts operating beyond the boundaries we gave it? Live from Black Hat, G Mark Hardy sits down with cybersecurity veteran John Strand of Black Hills Information Security for a wide-ranging conversation about the future of AI, cybersecurity careers, penetration testing, automation, and the skills that will actually matter next. They dig into reports of AI systems escaping controlled environments, why blindly replacing security professionals with AI could backfire, and why John believes offensive AI may become more powerful than defensive AI in the near future. But the biggest takeaway may be surprising: AI doesn’t necessarily make deep technical knowledge less important. It may make it more valuable than ever. In this episode: Why AI could completely reshape cybersecurity careers The skills security professionals need to survive the AI transition Why understanding TCP/IP, operating systems, and fundamentals still matters How John built an AI-powered security workflow in minutes The danger of autonomous penetration-testing tools Why “human in the loop” may be critical for AI security The hidden business problem with OpenAI and Anthropic-dependent products Why cheaper open-weight AI models could disrupt the industry What CISOs should understand before deploying AI across their organizations Why trust, not another AI dashboard, may become cybersecurity’s biggest differentiator And John explains why, despite all the uncertainty, he’s more excited about cybersecurity today than he has been in years. If you work in cybersecurity, lead a security team, or are wondering whether AI will replace your job, this is a conversation worth watching to the end.

    AI Is Breaking Out and Cybersecurity Isn’t Ready | John Strand - #296
  4. Jul 20

    Legal Developments Every CISO Needs to Know | Larry Dietz - #293

    Three major legal changes. One question every CISO should be asking: Is your cybersecurity program ready? Congress let a key FISA surveillance authority expire. The Supreme Court raised the bar on geofence warrants. The Department of Defense paused mandatory CMMC Level 2 certifications. At first glance, these seem like unrelated legal headlines. In reality, they all point to the same challenge: cybersecurity leaders must understand how changing laws affect data access, privacy, compliance, and personal liability. In this episode of CISO Tradecraft, host G. Mark Hardy sits down with attorney and cybersecurity expert Larry Dietz to break down what these legal developments actually mean for CISOs, not from a political perspective, but from a practical leadership perspective. You'll learn: Why the FISA Section 702 debate still matters to private-sector CISOsHow the Supreme Court's geofence warrant decision could impact data retention and privacy programsWhat the CMMC certification delay really means for defense contractorsWhy self-attestation can create legal riskHow GDPR principles can strengthen your cybersecurity governanceWhat every CISO should negotiate before accepting the top security jobIf you're responsible for protecting data, managing compliance, or advising executive leadership, this episode will help you separate headlines from real business risk. Subscribe for weekly insights that help cybersecurity leaders become more effective.

    Legal Developments Every CISO Needs to Know | Larry Dietz - #293
4.8
out of 5
49 Ratings

About

You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level. © Copyright 2025, National Security Corporation. All Rights Reserved

You Might Also Like