Episode notes
All links and images can be found on CISO Series. Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark , the producer of CISO Series , and Steve Zalewski . Joining us is our sponsored guest, Rob Allen. In this episode: The vulnerable stack Changing the structural economics Change the terrain The cost-benefit equation A huge thanks to our sponsor, ThreatLocker ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale.…
Defense in Depth
by CISO Series · English · Tech & Science
Defense in Depth, hosted by David Spark, Steve Zalewski, Geoff Belknap, and Edward Contreras, promises clear talk on cybersecurity's most controversial and confusing debates. Once a week we choose one controversial and popular cybersecurity debate and use the InfoSec community's insights to lead…
More from Defense in Depth
-
28 May 2026 · 33 min
What Does the Next Generation of Cloud Security Look Like?
All links and images can be found on CISO Series We know human-paced security controls can't be applied to autonomous AI agents. So what needs to change with CNAPP and cloud security? Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark , the producer of CISO Series , and Steve Zalewski . Joining us is our sponsored guest, Dan Benjamin , vp product - data, identity, and AI security, Palo Alto Networks . In this episode: The detection ceiling A category gap, not a feature gap Resilience by design An insider threat with no…
-
21 May 2026 · 27 min
The Dangers of Picking the Wrong Vendor
All links and images can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark , the producer of CISO Series , and Steve Zalewski . Joining us is our guest, Paul Guerra. In this episode: Read the contract How vendors win before the evaluation ends The fallout The real cost A huge thanks to our sponsor, Native Security Native makes secure-by-design inherent to how the cloud operates. It's the control plane for built-in cloud security, unifying and governing native controls, so security intent is…
-
14 May 2026 · 27 min
Why Cyber Startups Need CISO Advisors
All links and images can be found on CISO Series All security startups will tell you they talk to potential customers. The problem is that you limit your development when you only talk to CISOs who might buy. It's not the same guidance you'll get from a CISO who advises. Check out this post by Val Tsanev of the Cyber Risk Alliance for the discussion that is the basis of our conversation. This week's episode is co-hosted by me, David Spark , the producer of CISO Series , and Edward Contreras , senior evp and CISO, Frost Bank . Joining us is Steve Jensen , CISO, University of Maine System . In…
-
30 Apr 2026 · 38 min
How Do You Know If Your Backups Will Survive a Ransomware Attack?
All links and images can be found on CISO Series Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark , the producer of CISO Series , and Steve Zalewski . Joining us is our sponsored guest, Heath Renfrow , co-founder, Fenix24 . In this episode: Knowing which systems to save first Recovery is a business conversation, not an IT ticket Not all systems are created equal Recovery knowledge as a governed asset A huge thanks to our sponsor, Fenix24 Fenix24 is the world's leading breach recovery firm, providing rapid ransomware…
-
23 Apr 2026 · 27 min
What Makes a Successful Security Vendor Demo?
What Makes a Successful Security Vendor Demo? All links and images can be found on CISO Series . Check out this post from Adam Palmer for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark , the producer of CISO Series , and Geoff Belknap . Joining is Ken Beasley , BISO, Kaiser Permanente . In this episode: Show me the problem, not the product Walking in blind Discovery is the demo Define the use case, set the clock A huge thanks to our sponsor, Fenix24 Fenix24 is the world's leading breach recovery firm, providing rapid ransomware…
-
16 Apr 2026 · 28 min
Should You Use Native or 3rd Party Cloud Management Tools?
Should You Use Native or 3rd Party Cloud Management Tools? All links and images can be found on CISO Series . Check out this post from Steve Zalewski for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark , the producer of CISO Series , and Edward Contreras , senior evp and CISO, Frost Bank . Joining us is their sponsored guest, Gal Ordo , co-founder and CPO, Native . In this episode: More tools, more problems A gap in design Catching what slips through Competence over complexity A huge thanks to our sponsor, Native Security Native makes…
-
8 Oct 2026 · 33 min
Can SMBs Get the Same Security as Everyone Else?
All links and images can be found on CISO Series Check out this post for the discussion that is the basis of our conversation for this week's episode co-hosted by me, David Spark , the producer of CISO Series , and Steve Zalewski . Joining us is their sponsored guest, Mark Stockley , cybersecurity evangelist, ThreatDown . In this episode: The ripple effect The economics of ignoring SMB Let the defaults do the work Accountability doesn't get outsourced A huge thanks to our sponsor, ThreatDown ThreatDown MDR is a 24/7/365 security analyst service that explains and resolves suspicious endpoint…
-
1 Oct 2026 · 34 min
Why Do We Keep Complaining About the Same Issues in Cybersecurity?
All links and images can be found on CISO Series LinkedIn used to have a decent reputation among cybersecurity professionals. But lately, it feels like our feeds are relitigating the same debates every day, just with different faces. Has the situation changed? Check out this post by Allan Alford of NTT Global Data Centers for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark , the producer of CISO Series , and Geoff Belknap . Joining us is Howard Holton , founder, Phronia Counsel . In this episode: The clichés that say nothing A…
-
24 Sep 2026 · 35 min
Securing AI-Generated Open Source Code
All links and images can be found on CISO Series Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark , the producer of CISO Series , and Steve Zalewski . Joining us is our sponsored guest, Abby Kearns , CEO, ActiveState . In this episode: Trust, but nobody verifies The economics of trust just changed Implicit trust doesn't scale anymore Rethinking what "open" even means A huge thanks to our sponsor, ActiveState ActiveState gives security and engineering teams a single governed source for open source software. With…
-
21 Sep 2026 · 21 min
BONUS EPISODE: Super Cyber Friday Express - Hacking Vendor Selection
All links and images can be found on CISO Series This is a bonus episode of our brand new podcast, Super Cyber Friday Express — a 20-minute highlight version of our live one-hour show we do every available Friday at 1 p.m. Eastern. In this episode, David Spark is joined by Karl Mattson , founder and managing director of Squared Circle Ventures, and Howard Holton , founder and principal analyst at Phronia Counsel LLC, to discuss how your existing environment shapes what you buy next — and whether that's a strategy or just inertia. Watch the full one-hour show at Crowdcast . Subscribe to Super…
