The GC+CISO Connection

Shawn Tuma

The GC+CISO Connection Show explores how we can better foster collaboration between organizations’ legal departments and security teams, with a focus on the General Counsel (GCs) and Chief Information Security Officers (CISOs). In an era where cyber threats are rapidly evolving, the partnership between legal and cybersecurity leaders is more crucial than ever. The goal of this Show is to enhance dialogue, understanding, and cooperation between these critical roles to bolster organizational cyber resilience. More information about the show, as well as the book addressing the same topics, can be found at www.gccisoconnection.com

Episodes

  1. 5d ago

    Cyber Resilience, AI Governance, and the CISO’s Evolution with Andy Land

    Episode OverviewIn this episode of The GC+CISO Connection Show, Shawn Tuma sits down with Andy Land to discuss cyber resilience, AI governance, and the evolution of the CISO role in today’s business environment. Their conversation focuses on how the modern CISO must balance technical leadership with communication, business alignment, and stronger partnership with legal teams to help organizations build real resilience. About the GuestAndy Land is the General Manager of the CISO Executive Network (CISO ExecNet) and a recognized leader within the broader CISO community. He works closely with security executives across industries and brings a practical perspective on how the role of the CISO continues to mature as cyber risk, board expectations, and AI governance become more central to business leadership. Key Topics Covered Cyber Resilience as a Business Objective — Shawn and Andy discuss why resilience is the real mission and why organizations need to think beyond technical defense to business continuity and long-term strength.The Evolution of the CISO Role — The conversation highlights how the CISO role has changed from technical operator to strategic leader and business partner.AI Governance — AI governance is discussed as part of the broader transformation in cyber leadership and the growing need for legal and cyber teams to align on emerging technology risk.The GC-CISO Partnership — Shawn and Andy emphasize that the relationship between General Counsel and CISOs is becoming increasingly important in managing modern organizational risk.Humility, Communication, and Leadership — The episode underscores how communication skill, executive presence, and humility are foundational leadership traits for effective CISOs and strong cyber programs.Key Takeaways Cyber resilience should be treated as a business priority, not just a security program.The modern CISO must be able to communicate with executives, boards, and legal leaders, not just technical teams.AI governance is now part of the broader cyber leadership conversation and requires legal-cyber collaboration.GC-CISO alignment is a strategic advantage in a rapidly changing risk environment.Humility and clear communication are critical leadership traits in both legal and cyber roles. Resources & Links GC+CISO Connection Website: www.gccisoconnection.comApple Podcasts: https://podcasts.apple.com/au/podcast/the-gc-ciso-connection/id1771903573Join the LinkedIn Community: https://www.linkedin.com/groups/14499302/Connect with Shawn: https://www.spencerfane.com/professionals/shawn-tuma/About the HostShawn E. Tuma is a globally recognized cybersecurity attorney, author of The GC+CISO Connection: Uniting the Cyber Risk Defenders, and Partner at Spencer Fane LLP, where he leads the Cyber, Data, AI & Emerging Technology Practice Group. He has practiced cybersecurity law since 1999 and has been involved in thousands of critical incident response cases. He helps businesses protect their information and protect themselves from their information. Learn more at https://www.spencerfane.com/professionals/shawn-tuma/

    38 min
  2. Apr 28

    Crisis Management Lessons Every GC and CISO Needs | Jenny Gray | The GC+CISO Connection Show

    Episode OverviewIn this episode, host Shawn Tuma welcomes Jenny Gray, VP of Legal and Assistant General Counsel at Torrid, to discuss her firsthand experience guiding her previous employer, Tuesday Morning, through bankruptcy and liquidation — and what those hard-won lessons mean for GCs and CISOs facing cyber crises today. The conversation covers crisis team-building, transparent communication under pressure, the dangers of ego, and the growing connection between cyber attacks and financial collapse. About the GuestJenny Gray is Vice President of Legal and Assistant General Counsel at Torrid, a national publicly traded women's retailer. A Dallas native and SMU Law graduate, Jenny's career has spanned retail, governance, privacy, sustainability, and risk management.  Key Topics Covered The Tuesday Morning Bankruptcy — Jenny recounts leading legal through Tuesday Morning's 2023 bankruptcy filing and liquidation, from the quiet crisis before filing to handing the keys to a trustee by August 1 — all in roughly six months at lightning speed.Parallels Between Bankruptcy and Cyber Crisis — Shawn and Jenny explore striking similarities: the speed, the unpredictability, the victim-to-wrongdoer dynamic, and the critical need for a prepared, trusted team before crisis strikes.Transparency as a Crisis Strategy — Jenny shares how her leadership team chose to tell hard truths to employees even at the risk of people leaving — and was surprised by how many stayed because they wanted to finish well.Team, Trust, and Collaboration — Both agree that the relationships you build before a crisis determine how well you survive it. Knowing your team's skills, personalities, and roles before the bad day arrives is non-negotiable.Data Privacy, AI Governance, and Stewardship — The conversation expands to the responsibility organizations have to protect customer, employee, and applicant data, and how AI introduces new layers of accountability demanding the same principles of transparency and ownership.Key Takeaways Move slow when everything moves fast. In a crisis, the calmest person in the room wins. Slow down your communication, think deliberately, and resist the urge to react emotionally.Build your team before you need them. First introductions should never happen on the worst day of your professional life. Know your people, their roles, and how they think long before crisis arrives.Transparency builds trust — even in the worst situations. Telling hard truths, even imperfect ones, is better than silence. Tell people what you know today, and own it if it changes tomorrow.Ego is the enemy. Both legal and security leaders have strong, protective personalities. The willingness to say "I don't know — help me understand" is a superpower in any crisis.Cyber attacks can lead to bankruptcy. The connection is real and growing. Every GC and CISO needs to understand that a cyber crisis is simultaneously a financial, legal, and reputational crisis.Notable Quotes "In crisis, everything moves fast — so you move slow. You have to always be the calmest person on the outside in the room."— Jenny Gray, VP of Legal & Assistant General Counsel, Torrid"You are the victim of a cyber attack — but in law, regulation, even public opinion, you get transmogrified from the victim to the wrongdoer."— Shawn Tuma, Host, The GC+CISO Connection Show "The only thing I'm an expert in is being curious. The more I learn, the more I realize I need more support and more of a team to come beside me."— Jenny Gray, VP of Legal & Assistant General Counsel, Torrid Resources & Links GC+CISO Connection Website: www.gccisoconnection.comApple Podcasts: https://podcasts.apple.com/au/podcast/the-gc-ciso-connection/id1771903573Join the LinkedIn Community: https://www.linkedin.com/groups/14499302/Connect with Shawn: www.linkedin.com/in/shawnetuma/Connect with Jenny Gray: https://www.linkedin.com/in/jennyfer-gray/The GC+CISO Connection: Uniting the Cyber Risk Defenders by Shawn Tuma: www.gccisoconnection.comAbout the HostShawn E. Tuma is a globally recognized cybersecurity attorney, author of The GC+CISO Connection: Uniting the Cyber Risk Defenders, and Partner at Spencer Fane LLP, where he leads the Cyber, Data, AI & Emerging Technology Practice Group. He has practiced cybersecurity law since 1999 and has been involved in thousands of critical incident response cases. He helps businesses protect their information and protect themselves from their information. Learn more at www.shawnetuma.com.

    35 min
  3. 02/05/2025

    The GC+CISO Connection, Ep. 3: Bridging the Gap: Discussing In-House Legal and Cyber Collaboration with the Queens of Badassery, attorneys Nicola Hobeiche and Shereen El Domeiri

    In this episode of The GC+CISO Connection Show, host Shawn Tuma is joined by the Queens of Badassery, attorneys Nicola Hobeiche and Shereen El Domeiri, who bring decades of in-house legal experience to help dive deep into the vital relationship between in-house legal and security teams. Nicola and Shereen share their experiences, insights, and practical tips on building relationships and fostering collaboration across these critical departments. From preparing for critical incidents to navigating compliance with contracting, cybersecurity, privacy, and AI, to understanding roles and responsibilities, to Board reporting and CISO liability, this conversation explores how organizations can strengthen partnerships to protect and improve their organizations. Whether you're in legal, security, or executive leadership, this episode offers actionable advice for building stronger, more effective working relationships. Plus, hear about their own podcast, Counsel Brew, and what inspired them to share their expertise with the world!  | Bridging the Gap: Discussing In-House Legal and Cyber Collaboration with Two Badass Attorneys, Nicola Hobeiche and Shereen El Domeiri. Please be sure to "LIKE" and "SUBSCRIBE" so you will not miss future episodes! #GCCISOSHOW #GCCISOBOOK #GCCISO #GCCISOCONNECTION #GCxCISO #GC_CISO #GC #CISO #CIO #BISO #CLO, #CCO, #CFO, #CEO, #CIO, #CPO, #CTO, #Compliance, #CorporateGovernance, #Corporateattorney, #Corporatecompliance, #Corporatecounsel, #Corporategovernance, #Corporatelaw, #Corporatelawyer, #Cyber, #CyberInsurance, #CyberLaw, #CyberRisk, #CyberRiskManagement, #CyberResilience, #CyberSecurityAwareness, #DataBreach, #DataIsTheHotPotato, #DataPrivacy, #DataSecurity, #DallasCISO, #DFWCISO, #IncidentResponse, #Infosec, #Legal, #LegalAdvice, #Legaloperations, #PrivacyLaw, #PrivacyLaws, #RiskAssessment, #RiskManagement, #RiskManagementStrategy, #Security, #StrongerTogether, #TexasCISO, #LegalAndIT, #LegalAndCyber, #CollaborationMatters #CISO #DataProtection #CyberRisk #PrivacyLaw #ExecutiveLeadership #Teamwork,  #CounselBrew LINKS TO LINKEDIN PROFILES:Nicola Hobeiche https://www.linkedin.com/in/nicola-hobeiche-84699960/ Shereen El Domeiri https://www.linkedin.com/in/shereeneldomeiri/ CounselBrewhttps://counselbrew.com/ https://www.linkedin.com/company/counsel-brew

    32 min

About

The GC+CISO Connection Show explores how we can better foster collaboration between organizations’ legal departments and security teams, with a focus on the General Counsel (GCs) and Chief Information Security Officers (CISOs). In an era where cyber threats are rapidly evolving, the partnership between legal and cybersecurity leaders is more crucial than ever. The goal of this Show is to enhance dialogue, understanding, and cooperation between these critical roles to bolster organizational cyber resilience. More information about the show, as well as the book addressing the same topics, can be found at www.gccisoconnection.com