The Cybersecurity Readiness Podcast Series

Dr. Dave Chatterjee

The Cybersecurity Readiness Podcast Series provides a reflective, thought-provoking, and jargon-free discussion on how to enhance the state of cybersecurity at an individual, organizational, and national level. As of September 2, 2024, the podcast series has produced over 70 episodes, been downloaded over 10K times, and has listeners in 105 countries. The podcast episodes are used in classrooms and for corporate training and serve as insight sources in research and publications. Host Dr. Dave Chatterjee converses with subject matter experts, business and technology leaders, trainers and educators, and members of user communities. He has been studying cybersecurity for over a decade. He has delivered talks, conducted webinars, consulted with companies, and served on a cybersecurity SWAT team with Chief Information Security Officers (CISOs). Dr. Chatterjee is a Visiting Professor at Duke University and has served as a tenured professor at The Terry College of Business at the University of Georgia. Connect with Dr. Chatterjee on these platforms: LinkedIn: https://www.linkedin.com/in/dchatte/ Website: https://dchatte.com/

  1. 2d ago

    Episode 113 - The EU Cyber Resilience Act Countdown: Why U.S. Companies Can't Afford to Look Away

    In Episode 113 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Mark Lambert, Chief Product Officer at ArmorCode, to unpack the European Union's Cyber Resilience Act (CRA) and why U.S. companies cannot treat it as someone else's problem. Dr. Chatterjee opens with a scenario that captures the stakes: a mid-sized U.S. software company discovers one of its products is being actively exploited, investigates, patches, and notifies its customers within three days — a response most frameworks would call fast, but one that violates the CRA, whose clock for reporting an actively exploited vulnerability starts at 24 hours, not three days. Lambert, who works daily with organizations on vulnerability management, explains that the CRA functions like GDPR for security: any software that ships into Europe, or that relies on supporting infrastructure serving European users, falls under its scope, and non-compliance carries fines of up to 2.5% of global revenue or €15 million, whichever is higher. The conversation walks through the CRA's three distinct notification clocks — a 24-hour early warning, a 72-hour full notification, and a 14-day final report after a fix becomes available — and dispenses with the idea that lacking sophisticated detection capabilities is a viable defense; the law expects secure-by-design practices and detection capability to already be in place before an incident occurs. Analyzed throughout the episode through Dr. Chatterjee's Commitment–Preparedness–Discipline (CPD) Framework, the discussion also covers what well-prepared organizations are already doing — operationalizing vulnerability management programs and building real-time asset inventories — and closes with a shared view that regulatory pressure, while unwelcome, ultimately pushes organizations toward the security discipline they should be practicing regardless of legal mandate. To access and download the entire podcast summary with discussion highlights - https://www.dchatte.com/episode-113-the-eu-cyber-resilience-act-countdown-why-u-s-companies-cant-afford-to-look-away/ Connect with Host Dr. Dave Chatterjee LinkedIn: https://www.linkedin.com/in/dchatte/ Website: https://dchatte.com/ Books Published The DeepFake Conspiracy Cybersecurity Readiness: A Holistic and High-Performance Approach Articles & Cases Published Chatterjee, D. (2026). The Cryptographic Reckoning: Why Quantum Readiness Begins with Agility, Not Algorithms, The INFORMS Analytics Magazine, June 26, 2026 Chatterjee, D. (2026). The New Digital Fragility: How AI-Enhanced Cyber Threats Are Reshaping Operational Resilience, The INFORMS Analytics Magazine, March 4, 2026 Chatterjee, D. (2026). Root: Automating the Remediation Gap, Ivey Publishing, Jan 7, 2026. Ramasastry, C. and Chatterjee, D. (2025). Trusona: Recruiting For The Hacker Mindset, Ivey Publishing, Oct 3, 2025. Chatterjee, D. and Leslie, A. (2024). “Ignorance is not bliss: A human-centered whole-of-enterprise approach to cybersecurity preparedness,” Business Horizons, Accepted on Oct 29, 2024. Isik, O., Chatterjee, D., and Lourenco, D.A. (2024). “Getting Cybersecurity Right,” California Management Review — Insights, Accepted for Publication, July 8, 2024. Chatterjee, D. (2023). “Mission critical – How American Cancer Society successfully and securely migrated to the cloud amid the pandemic,” I by IMD, March 13, 2023. Chatterjee, D. (2022). “Preventing security breaches must start at the top,” I by IMD, September 28, 2022, Institute for Management Development, Lausanne, Switzerland Chatterjee, D. (2022). “Making Cybersecurity Readiness Mainstream,” Executive Blog Post, NETSPI, March 1, 2022 Benz, M. and Chatterjee, D. (2020). “Calculated Risk? A Cybersecurity Evaluation Tool for SMEs,” Business Horizons, available online from May 4, 2020 Chatterjee, D. (2019). “Should Executives Go To Jail Over Cyber Attacks,” Journal of Organizational Computing and Electronic Commerce, Vol 29, Issue 1, pp. 1-3. Abraham, C., Chatterjee, D., and Sims, R. (2019). “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” Business Horizons, July 2019.

  2. Sep 2

    Episode 112 -- When the EHR Goes Dark: Patient Safety Meets Cybersecurity Governance

    In Episode 112 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Dr. Mark Yoffe, a board-certified internal medicine physician who has also built deep expertise in cybersecurity, to examine a question most healthcare organizations have not fully reckoned with: what actually happens to patient care when the electronic health record goes dark. Dr. Chatterjee opens with a sobering scenario — a nurse unable to confirm whether a cardiac patient's anticoagulant was administered overnight because the EHR is degraded, resulting in a double dose — and notes that variations of this scenario have occurred during real ransomware attacks and extended downtime events, even though most healthcare organizations have not mapped which clinical dependencies fail first or pre-assigned who decides what when systems cannot be trusted. Dr. Yoffe, who bridges internal medicine and information security, explains how the same words — confidentiality, integrity, availability — carry weight in both professions, and walks through what actually happens on the floor when digital systems go down: clinicians shift from an "information push" environment, where alerts and updates come to them, to an "information pull" environment, where they must actively seek out information, usually from other humans, because the chart itself can no longer be trusted. The conversation moves through the compensatory mechanisms hospitals fall back on — written charts, physical examination, and the judgment clinicians rely on when information is incomplete — and into how security professionals can translate technical metrics like uptime into the language leadership and clinicians actually understand: patient care and mission impact. Analyzed throughout the episode through Dr. Chatterjee's Commitment–Preparedness–Discipline (CPD) Framework, the discussion also tackles the distinct governance challenge posed by AI in healthcare — a tool that, unlike a scalpel or a hammer, is never quite the same tool twice — and closes with a shared conviction that preparation is not a once-a-year tabletop exercise but a daily discipline that determines how clinicians and organizations perform when systems, and stakes, are at their worst. To access and download the entire podcast summary with discussion highlights - https://www.dchatte.com/episode-112-when-the-ehr-goes-dark-patient-safety-meets-cybersecurity-governance/ Connect with Host Dr. Dave Chatterjee LinkedIn: https://www.linkedin.com/in/dchatte/ Website: https://dchatte.com/ Books Published The DeepFake Conspiracy Cybersecurity Readiness: A Holistic and High-Performance Approach Articles & Cases Published Chatterjee, D. (2026). The Cryptographic Reckoning: Why Quantum Readiness Begins with Agility, Not Algorithms, The INFORMS Analytics Magazine, June 26, 2026 Chatterjee, D. (2026). The New Digital Fragility: How AI-Enhanced Cyber Threats Are Reshaping Operational Resilience, The INFORMS Analytics Magazine, March 4, 2026 Chatterjee, D. (2026). Root: Automating the Remediation Gap, Ivey Publishing, Jan 7, 2026. Ramasastry, C. and Chatterjee, D. (2025). Trusona: Recruiting For The Hacker Mindset, Ivey Publishing, Oct 3, 2025. Chatterjee, D. and Leslie, A. (2024). “Ignorance is not bliss: A human-centered whole-of-enterprise approach to cybersecurity preparedness,” Business Horizons, Accepted on Oct 29, 2024. Isik, O., Chatterjee, D., and Lourenco, D.A. (2024). “Getting Cybersecurity Right,” California Management Review — Insights, Accepted for Publication, July 8, 2024. Chatterjee, D. (2023). “Mission critical – How American Cancer Society successfully and securely migrated to the cloud amid the pandemic,” I by IMD, March 13, 2023. Chatterjee, D. (2022). “Preventing security breaches must start at the top,” I by IMD, September 28, 2022, Institute for Management Development, Lausanne, Switzerland Chatterjee, D. (2022). “Making Cybersecurity Readiness Mainstream,” Executive Blog Post, NETSPI, March 1, 2022 Benz, M. and Chatterjee, D. (2020). “Calculated Risk? A Cybersecurity Evaluation Tool for SMEs,” Business Horizons, available online from May 4, 2020 Chatterjee, D. (2019). “Should Executives Go To Jail Over Cyber Attacks,” Journal of Organizational Computing and Electronic Commerce, Vol 29, Issue 1, pp. 1-3. Abraham, C., Chatterjee, D., and Sims, R. (2019). “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” Business Horizons, July 2019.

  3. Aug 19

    Episode 111 -- Leadership Intention vs. Operational Reality: A CPD Lens on SMB Cybersecurity

    In Episode 111 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Bruno Lecoq, CEO of BEMO, to examine the gap between executive intention and operational security reality in small and medium-sized organizations, and what it costs when resource trade-offs, unclear ownership, and optimism bias quietly undermine programs that look sound on paper. Drawing on his nearly sixteen years at BEMO and twenty years at Microsoft before that, working with companies of 10 to 1,000 users across multiple verticals, Bruno argues that the recurring failure point is rarely the tools; it is the absence of clear ownership, aligned resources, and sustained discipline. The conversation moves through why IT alone cannot own security, how the function's reporting line shapes whether it is treated as a cost center or a strategic capability, and a detailed walk-through of a SOC 2 "fire drill" scenario that Dr. Chatterjee analyzes through his Commitment–Preparedness–Discipline (CPD) Framework. The discussion also covers how BEMO uses AI-driven log review and unannounced tabletop exercises to keep clients honest about their true readiness, why Bruno turns away prospects who treat compliance as a paperwork exercise rather than a genuine security commitment, and why he believes cybersecurity and compliance, approached the right way, are a competitive advantage rather than a cost of doing business. To access and download the entire podcast summary with discussion highlights - https://www.dchatte.com/episode-111-closing-the-gap-between-leadership-intention-and-operational-security-reality-a-cpd-lens-on-smb-cybersecurity-governance/ Connect with Host Dr. Dave Chatterjee LinkedIn: https://www.linkedin.com/in/dchatte/ Website: https://dchatte.com/ Books Published The DeepFake Conspiracy Cybersecurity Readiness: A Holistic and High-Performance Approach Articles & Cases Published Chatterjee, D. (2026). The Cryptographic Reckoning: Why Quantum Readiness Begins with Agility, Not Algorithms, The INFORMS Analytics Magazine, June 26, 2026 Chatterjee, D. (2026). The New Digital Fragility: How AI-Enhanced Cyber Threats Are Reshaping Operational Resilience, The INFORMS Analytics Magazine, March 4, 2026 Chatterjee, D. (2026). Root: Automating the Remediation Gap, Ivey Publishing, Jan 7, 2026. Ramasastry, C. and Chatterjee, D. (2025). Trusona: Recruiting For The Hacker Mindset, Ivey Publishing, Oct 3, 2025. Chatterjee, D. and Leslie, A. (2024). “Ignorance is not bliss: A human-centered whole-of-enterprise approach to cybersecurity preparedness,” Business Horizons, Accepted on Oct 29, 2024. Isik, O., Chatterjee, D., and Lourenco, D.A. (2024). “Getting Cybersecurity Right,” California Management Review — Insights, Accepted for Publication, July 8, 2024. Chatterjee, D. (2023). “Mission critical – How American Cancer Society successfully and securely migrated to the cloud amid the pandemic,” I by IMD, March 13, 2023. Chatterjee, D. (2022). “Preventing security breaches must start at the top,” I by IMD, September 28, 2022, Institute for Management Development, Lausanne, Switzerland Chatterjee, D. (2022). “Making Cybersecurity Readiness Mainstream,” Executive Blog Post, NETSPI, March 1, 2022 Benz, M. and Chatterjee, D. (2020). “Calculated Risk? A Cybersecurity Evaluation Tool for SMEs,” Business Horizons, available online from May 4, 2020 Chatterjee, D. (2019). “Should Executives Go To Jail Over Cyber Attacks,” Journal of Organizational Computing and Electronic Commerce, Vol 29, Issue 1, pp. 1-3. Abraham, C., Chatterjee, D., and Sims, R. (2019). “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” Business Horizons, July 2019.

  4. Aug 5

    Episode 110 -- When the Attacker Builds the Key: Frontier AI and the Future of Continuous Penetration Testing

    In Episode 110 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Dr. Varin Khera, Co-Founder and Chief Technology Officer of SecStrike and Head of Asia Pacific at Yarix, to examine how frontier AI models have shifted the offense-defense balance in cybersecurity, and why the annual or semi-annual penetration test — long treated as a reliable baseline control — can no longer keep pace with adversaries who reason adaptively, chain misconfigurations across dozens of systems, and build their own attack playbooks in real time. Dr. Khera, who sits on both sides of the AI arms race — building EchoStrike, SecStrike’s AI-driven, model-agnostic “symbiotic penetration testing” platform, while also advising enterprise clients through Yarix on how to defend against that same class of technology — walks through how frontier AI differs from the automation that preceded it. Using a locksmith analogy, he explains that older AI tools executed a fixed playbook, while frontier models construct the attack path themselves, discovering and exploiting misconfigurations a once-a-year human-led test would never have the time or reach to find. The conversation details the architecture behind EchoStrike: Crimson Nexus, a persistent, fingerprint-based knowledge engine that learns from past human decisions; the Red Engine, which orchestrates and executes validation actions; Recon, which continuously maps external attack surfaces; and the patent-pending Adaptive Threat Validation (ATV) engine that ties the components together and escalates high-judgment decisions to a human reviewer before any high-impact action is taken. Analyzed through Dr. Chatterjee’s Commitment–Preparedness–Discipline (CPD) Framework, the episode also addresses how security leaders should frame the case for continuous validation to the board — not as a technology purchase, but as a decision about whether to close a known and growing risk — and closes with a rapid-fire exchange on the misconceptions, governance gaps, and accountability questions defining this next phase of AI-driven offensive and defensive security. To access and download the entire podcast summary with discussion highlights - https://www.dchatte.com/episode-110-when-the-attacker-builds-the-key-frontier-ai-and-the-future-of-continuous-penetration-testing/ Connect with Host Dr. Dave Chatterjee LinkedIn: https://www.linkedin.com/in/dchatte/ Website: https://dchatte.com/ Books Published The DeepFake Conspiracy Cybersecurity Readiness: A Holistic and High-Performance Approach Articles & Cases Published Chatterjee, D. (2026). The Cryptographic Reckoning: Why Quantum Readiness Begins with Agility, Not Algorithms, The INFORMS Analytics Magazine, June 26, 2026 Chatterjee, D. (2026). The New Digital Fragility: How AI-Enhanced Cyber Threats Are Reshaping Operational Resilience, The INFORMS Analytics Magazine, March 4, 2026 Chatterjee, D. (2026). Root: Automating the Remediation Gap, Ivey Publishing, Jan 7, 2026. Ramasastry, C. and Chatterjee, D. (2025). Trusona: Recruiting For The Hacker Mindset, Ivey Publishing, Oct 3, 2025. Chatterjee, D. and Leslie, A. (2024). “Ignorance is not bliss: A human-centered whole-of-enterprise approach to cybersecurity preparedness,” Business Horizons, Accepted on Oct 29, 2024. Isik, O., Chatterjee, D., and Lourenco, D.A. (2024). “Getting Cybersecurity Right,” California Management Review — Insights, Accepted for Publication, July 8, 2024. Chatterjee, D. (2023). “Mission critical – How American Cancer Society successfully and securely migrated to the cloud amid the pandemic,” I by IMD, March 13, 2023. Chatterjee, D. (2022). “Preventing security breaches must start at the top,” I by IMD, September 28, 2022, Institute for Management Development, Lausanne, Switzerland Chatterjee, D. (2022). “Making Cybersecurity Readiness Mainstream,” Executive Blog Post, NETSPI, March 1, 2022 Benz, M. and Chatterjee, D. (2020). “Calculated Risk? A Cybersecurity Evaluation Tool for SMEs,” Business Horizons, available online from May 4, 2020 Chatterjee, D. (2019). “Should Executives Go To Jail Over Cyber Attacks,” Journal of Organizational Computing and Electronic Commerce, Vol 29, Issue 1, pp. 1-3. Abraham, C., Chatterjee, D., and Sims, R. (2019). “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” Business Horizons, July 2019.

  5. Jul 22

    Episode 109 - From Alert Fatigue to Agentic Defense: Redesigning the Human Role in the AI-Native SOC

    In Episode 109 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Joshua Weinick, AI Automation Engineer at Blink Ops, to examine a question every security leader is now facing: what happens when the volume, velocity, and variety of cyber threats exceed what any human-staffed security operations center (SOC) can handle, and what role do humans play in a security function that increasingly depends on AI agents executing at machine speed. Drawing on his background in cybersecurity consulting and his time embedded in Fortune 500 SOCs at Ernst & Young, Josh traces the limitations of legacy SOAR automation — rigid, Python-coded pipelines that broke whenever an edge case or a system change occurred — and explains why agentic AI, unlike its predecessors, is built to absorb change rather than collapse under it. The conversation moves through the three forces breaking the traditional SOC model — overwhelming alert volume, attack speed that has compressed response windows from hours to minutes, and the cognitive toll of analyst burnout — and arrives at a reframed model Josh calls “human after the loop,” in which agentic systems take initial action within guardrails while humans review, audit, and reverse where needed. The discussion examines what this shift means for emerging security talent, walks through a real-world 3 a.m. incident scenario that illustrates why a 45-minute human approval delay is now functionally equivalent to no response at all, and lays out five concrete steps organizations can take to begin the transition responsibly. Analyzed through Dr. Chatterjee's Commitment–Preparedness–Discipline (CPD) Framework, the episode reframes the SOC transformation not as a story about replacing security professionals, but about redesigning where human judgment adds the most value once the mundane, repetitive, and time-critical work is handled by governed AI systems. To access and download the entire podcast summary with discussion highlights: https://www.dchatte.com/episode-109-agentic-ai-in-the-security-operations-center-redesigning-the-human-role-in-automated-threat-detection-and-response/ Connect with Host Dr. Dave Chatterjee LinkedIn: https://www.linkedin.com/in/dchatte/ Website: https://dchatte.com/ Books Published The DeepFake Conspiracy Cybersecurity Readiness: A Holistic and High-Performance Approach Articles & Cases Published Chatterjee, D. (2026). The Cryptographic Reckoning: Why Quantum Readiness Begins with Agility, Not Algorithms, The INFORMS Analytics Magazine, June 26, 2026 Chatterjee, D. (2026). The New Digital Fragility: How AI-Enhanced Cyber Threats Are Reshaping Operational Resilience, The INFORMS Analytics Magazine, March 4, 2026 Chatterjee, D. (2026). Root: Automating the Remediation Gap, Ivey Publishing, Jan 7, 2026. Ramasastry, C. and Chatterjee, D. (2025). Trusona: Recruiting For The Hacker Mindset, Ivey Publishing, Oct 3, 2025. Chatterjee, D. and Leslie, A. (2024). “Ignorance is not bliss: A human-centered whole-of-enterprise approach to cybersecurity preparedness,” Business Horizons, Accepted on Oct 29, 2024. Isik, O., Chatterjee, D., and Lourenco, D.A. (2024). “Getting Cybersecurity Right,” California Management Review — Insights, Accepted for Publication, July 8, 2024. Chatterjee, D. (2023). “Mission critical – How American Cancer Society successfully and securely migrated to the cloud amid the pandemic,” I by IMD, March 13, 2023. Chatterjee, D. (2022). “Preventing security breaches must start at the top,” I by IMD, September 28, 2022, Institute for Management Development, Lausanne, Switzerland Chatterjee, D. (2022). “Making Cybersecurity Readiness Mainstream,” Executive Blog Post, NETSPI, March 1, 2022 Benz, M. and Chatterjee, D. (2020). “Calculated Risk? A Cybersecurity Evaluation Tool for SMEs,” Business Horizons, available online from May 4, 2020 Chatterjee, D. (2019). “Should Executives Go To Jail Over Cyber Attacks,” Journal of Organizational Computing and Electronic Commerce, Vol 29, Issue 1, pp. 1-3. Abraham, C., Chatterjee, D., and Sims, R. (2019). “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” Business Horizons, July 2019.

  6. Jul 8

    Episode 108 -- The Invisible Foundation: Why DNS Security Is the Governance Gap No One Is Watching

    In Episode 108 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Scott Harrell, President and Chief Executive Officer of Infoblox and former leader of Cisco's $20 billion enterprise networking business — to examine one of the most consequential security blind spots in modern enterprise governance: the foundational network infrastructure layer that every other security investment depends on, and that almost no organization actively governs. The episode opens with the October 2025 Amazon Web Services outage, in which a single automated misconfiguration in a core routing service triggered a global cascade that took down AI services, financial platforms, and consumer applications worldwide, producing an estimated $581 million in losses. The cause was not a sophisticated cyber attack. It was a governance decision that had never been made — nobody was actively watching the foundational layer. That event becomes the opening frame for a conversation about DNS, DHCP, and IP address management: the three-part infrastructure, collectively known as DDI, that assigns every device an address, maps every application name to a network location, and routes every piece of digital traffic to its destination. When it works, it is invisible. When it fails — or when an attacker exploits it — everything built on top of it stops. Harrell's central argument is structural: 92% of all malware relies on DNS for its initial call-out to attacker-controlled infrastructure. The first thing any malware does when it lands on a network is resolve a malicious domain — and if that DNS request is blocked, the entire incident cascade never occurs. The payload is never downloaded. Lateral movement never begins. Privilege escalation never follows. The problem is that most enterprise security stacks are built to detect and respond to malware after it has activated — not to intercept the first domain resolution that enables everything that follows. This is the difference between reactive and preemptive security, and it is a governance choice that shows up in budget allocations: currently, only 5% of enterprise security spending goes to preemptive activities, with 95% consumed by detection and response. Gartner projects that organizations will need to reach a 50/50 split by 2030. The conversation addresses how to make the governance case for foundational infrastructure investment, what differentiated DNS security looks like, how agentic AI is about to make network complexity exponentially harder to manage, and what three metrics every senior leader should be demanding from their security teams. Analyzed through Dr. Chatterjee's Commitment–Preparedness–Discipline (CPD) Framework, the episode reframes network infrastructure security from an IT operational matter into a board-level governance imperative. The episode's core message is neither technical nor vendor-specific: the organizations that will withstand the next breach are not those with the most sophisticated detection tools — they are those that have decided to govern the layer on which everything else depends. To access and download the entire podcast summary with discussion highlights - https://www.dchatte.com/episode-108-the-invisible-foundation-why-dns-security-is-the-governance-gap-no-one-is-watching/ Connect with Host Dr. Dave Chatterjee LinkedIn: https://www.linkedin.com/in/dchatte/ Website: https://dchatte.com/ Books Published The DeepFake Conspiracy Cybersecurity Readiness: A Holistic and High-Performance Approach Articles & Cases Published Chatterjee, D. (2026). The Cryptographic Reckoning: Why Quantum Readiness Begins with Agility, Not Algorithms, The INFORMS Analytics Magazine, June 26, 2026 Chatterjee, D. (2026). The New Digital Fragility: How AI-Enhanced Cyber Threats Are Reshaping Operational Resilience, The INFORMS Analytics Magazine, March 4, 2026 Chatterjee, D. (2026). Root: Automating the Remediation Gap, Ivey Publishing, Jan 7, 2026. Ramasastry, C. and Chatterjee, D. (2025). Trusona: Recruiting For The Hacker Mindset, Ivey Publishing, Oct 3, 2025. Chatterjee, D. and Leslie, A. (2024). “Ignorance is not bliss: A human-centered whole-of-enterprise approach to cybersecurity preparedness,” Business Horizons, Accepted on Oct 29, 2024. Isik, O., Chatterjee, D., and Lourenco, D.A. (2024). “Getting Cybersecurity Right,” California Management Review — Insights, Accepted for Publication, July 8, 2024. Chatterjee, D. (2023). “Mission critical – How American Cancer Society successfully and securely migrated to the cloud amid the pandemic,” I by IMD, March 13, 2023. Chatterjee, D. (2022). “Preventing security breaches must start at the top,” I by IMD, September 28, 2022, Institute for Management Development, Lausanne, Switzerland Chatterjee, D. (2022). “Making Cybersecurity Readiness Mainstream,” Executive Blog Post, NETSPI, March 1, 2022 Benz, M. and Chatterjee, D. (2020). “Calculated Risk? A Cybersecurity Evaluation Tool for SMEs,” Business Horizons, available online from May 4, 2020 Chatterjee, D. (2019). “Should Executives Go To Jail Over Cyber Attacks,” Journal of Organizational Computing and Electronic Commerce, Vol

  7. Jun 24

    Episode 107 -- Compliant but Exposed: Rethinking GRC for Real Security

    In Episode 107 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Richa Kaul, Founder and Chief Executive Officer of Complyance and a former public sector technology policy leader, to address one of the most consequential misunderstandings in enterprise security governance: the assumption that compliance equals security. Opening with two recent and high-profile incidents — the May 2025 ransomware attack on Marks & Spencer, which halted online operations for weeks and generated estimated losses exceeding £300 million, and a concurrent third-party support provider compromise that exposed customer data across multiple platforms including Discord — Dr. Chatterjee establishes the episode’s central premise: organizations that invest heavily in GRC platforms, generate dashboards full of green indicators, and maintain formal compliance certifications can still be catastrophically breached. The gap between compliance and security is not theoretical. It is structural and where attackers operate. Kaul explains the root cause with precision. Traditional GRC tools were built to centralize data and automate workflow notifications — functions that reduce administrative burden but do not reduce risk. The result is a compliance theater dynamic in which organizations check boxes, pass periodic audits, and receive certifications that say little about their actual security posture. The Complyance platform is built on a different philosophy: compliance with standards should be a byproduct of genuinely good security practices, not the objective in its own right. The episode explores the architecture of intelligent GRC: continuous monitoring across all integrated sources of truth, agentic AI that automates evidence collection and remediation guidance, tiered third-party risk programs that apply scrutiny proportional to vendor criticality, and risk quantification frameworks that translate security signals into board-level governance decisions. Kaul is equally precise about what GRC platforms cannot do: they cannot substitute for operational security teams, and no platform — however sophisticated — can protect an organization whose leadership has not committed to genuine risk reduction as the governing objective. Analyzed through Dr. Chatterjee’s Commitment–Preparedness–Discipline (CPD) framework, the conversation reframes GRC from a compliance function into a governance discipline. The episode’s central message is neither technical nor vendor-specific: the organizations that will withstand the next breach are not those with the most compliance certifications — they are those that have claimed ownership of the problem, built the continuous processes to address it, and institutionalized the discipline to keep those processes operating after the audit is over. To access and download the entire podcast summary with discussion highlights - https://www.dchatte.com/episode-107-compliant-but-exposed-rethinking-grc-for-real-security/ Connect with Host Dr. Dave Chatterjee LinkedIn: https://www.linkedin.com/in/dchatte/ Website: https://dchatte.com/ Books Published The DeepFake Conspiracy Cybersecurity Readiness: A Holistic and High-Performance Approach Articles & Cases Published Chatterjee, D. (2026). Root: Automating the Remediation Gap, Ivey Publishing, Jan 7, 2026. Ramasastry, C. and Chatterjee, D. (2025). Trusona: Recruiting For The Hacker Mindset, Ivey Publishing, Oct 3, 2025. Chatterjee, D. and Leslie, A. (2024). “Ignorance is not bliss: A human-centered whole-of-enterprise approach to cybersecurity preparedness,” Business Horizons, Accepted on Oct 29, 2024. Isik, O., Chatterjee, D., and Lourenco, D.A. (2024). “Getting Cybersecurity Right,” California Management Review — Insights, Accepted for Publication, July 8, 2024. Chatterjee, D. (2023). “Mission critical – How American Cancer Society successfully and securely migrated to the cloud amid the pandemic,” I by IMD, March 13, 2023. Chatterjee, D. (2022). “Preventing security breaches must start at the top,” I by IMD, September 28, 2022, Institute for Management Development, Lausanne, Switzerland Chatterjee, D. (2022). “Making Cybersecurity Readiness Mainstream,” Executive Blog Post, NETSPI, March 1, 2022 Benz, M. and Chatterjee, D. (2020). “Calculated Risk? A Cybersecurity Evaluation Tool for SMEs,” Business Horizons, available online from May 4, 2020 Chatterjee, D. (2019). “Should Executives Go To Jail Over Cyber Attacks,” Journal of Organizational Computing and Electronic Commerce, Vol 29, Issue 1, pp. 1-3. Abraham, C., Chatterjee, D., and Sims, R. (2019). “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” Business Horizons, July 2019.

  8. Jun 10

    Episode 106 -- The Invisible Attack Surface: Zero Trust for SAP and ERP Environments

    In Episode 106 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Holger Hügel, Chief Technology Officer of SecurityBridge and a global authority on SAP cybersecurity with over 26 years of experience — to address a governance blind spot that exists inside the security perimeters of even the most mature enterprise organizations: the SAP environment. Opening with the August 2024 ransomware attack on Stoli Group USA — where attackers went straight for the company's SAP enterprise resource planning (ERP) system, disrupting financial operations and contributing directly to a bankruptcy filing within three months — Dr. Chatterjee frames the episode's central challenge: organizations can have zero trust architecture, network segmentation, and identity governance fully deployed across their IT landscape, and still be critically exposed, because most CISOs have never formally claimed accountability for SAP security, and most SAP teams do not think of themselves as part of the security function. Hügel explains the structural gap at the heart of this problem. SAP systems are simultaneously the most business-critical and the least security-governed assets in most large organizations. The C-suite depends on them for financial operations, payroll, procurement, and supply chain continuity, yet SAP teams and security teams speak different languages, operate under different budgets, and rarely collaborate. SAP departments typically define "security" as managing user authorizations and privileges — a narrow interpretation that leaves configuration drift, patch backlogs, and monitoring gaps entirely unaddressed. Analyzed through Dr. Chatterjee's Commitment–Preparedness–Discipline (CPD) framework, the conversation translates SAP cybersecurity from a technical niche into a governance imperative. The Medtronic case study demonstrates what good looks like: a CISO who crossed the organizational divide, sponsored SAP hardening from the cybersecurity budget, built a continuous patch management process, and created the governance structure that allowed the team to respond to an out-of-band vulnerability within hours rather than weeks. The episode's central message is neither technical nor abstract: the organizations that will survive the next ERP-targeted ransomware attack are not those with the most sophisticated tools — they are the ones that have claimed ownership of the problem, built the processes to address it continuously, and created the cross-functional governance structures that SAP and cybersecurity teams cannot build on their own. To access and download the entire podcast summary with discussion highlights - https://www.dchatte.com/episode-106-the-invisible-attack-surface-zero-trust-for-sap-and-erp-environments/ Connect with Host Dr. Dave Chatterjee LinkedIn: https://www.linkedin.com/in/dchatte/ Website: https://dchatte.com/ Books Published The DeepFake Conspiracy Cybersecurity Readiness: A Holistic and High-Performance Approach Articles & Cases Published Chatterjee, D. (2026). Root: Automating the Remediation Gap, Ivey Publishing, Jan 7, 2026. Ramasastry, C. and Chatterjee, D. (2025). Trusona: Recruiting For The Hacker Mindset, Ivey Publishing, Oct 3, 2025. Chatterjee, D. and Leslie, A. (2024). “Ignorance is not bliss: A human-centered whole-of-enterprise approach to cybersecurity preparedness,” Business Horizons, Accepted on Oct 29, 2024. Isik, O., Chatterjee, D., and Lourenco, D.A. (2024). “Getting Cybersecurity Right,” California Management Review — Insights, Accepted for Publication, July 8, 2024. Chatterjee, D. (2023). “Mission critical – How American Cancer Society successfully and securely migrated to the cloud amid the pandemic,” I by IMD, March 13, 2023. Chatterjee, D. (2022). “Preventing security breaches must start at the top,” I by IMD, September 28, 2022, Institute for Management Development, Lausanne, Switzerland Chatterjee, D. (2022). “Making Cybersecurity Readiness Mainstream,” Executive Blog Post, NETSPI, March 1, 2022 Benz, M. and Chatterjee, D. (2020). “Calculated Risk? A Cybersecurity Evaluation Tool for SMEs,” Business Horizons, available online from May 4, 2020 Chatterjee, D. (2019). “Should Executives Go To Jail Over Cyber Attacks,” Journal of Organizational Computing and Electronic Commerce, Vol 29, Issue 1, pp. 1-3. Abraham, C., Chatterjee, D., and Sims, R. (2019). “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” Business Horizons, July 2019.

5
out of 5
3 Ratings

About

The Cybersecurity Readiness Podcast Series provides a reflective, thought-provoking, and jargon-free discussion on how to enhance the state of cybersecurity at an individual, organizational, and national level. As of September 2, 2024, the podcast series has produced over 70 episodes, been downloaded over 10K times, and has listeners in 105 countries. The podcast episodes are used in classrooms and for corporate training and serve as insight sources in research and publications. Host Dr. Dave Chatterjee converses with subject matter experts, business and technology leaders, trainers and educators, and members of user communities. He has been studying cybersecurity for over a decade. He has delivered talks, conducted webinars, consulted with companies, and served on a cybersecurity SWAT team with Chief Information Security Officers (CISOs). Dr. Chatterjee is a Visiting Professor at Duke University and has served as a tenured professor at The Terry College of Business at the University of Georgia. Connect with Dr. Chatterjee on these platforms: LinkedIn: https://www.linkedin.com/in/dchatte/ Website: https://dchatte.com/