CISO Tradecraft® Podcast By CISO Tradecraft® cover art

CISO Tradecraft®

CISO Tradecraft®

By: CISO Tradecraft®
Listen for free

About this listen

Welcome to CISO Tradecraft®, your guide to mastering the art of being a top-tier Chief Information Security Officer (CISO). Our podcast empowers you to elevate your information security skills to an executive level. Join us on this journey through the domains of effective CISO leadership. © Copyright 2025, National Security Corporation. All Rights Reserved© Copyright 2025, National Security Corporation. All Rights Reserved Career Success Economics Management Management & Leadership
Episodes
  • #236 - Build a World Class GRC Program (with Matt Hillary)
    Jun 9 2025

    In this episode of CISO Tradecraft, host G Mark Hardy sits down with Matt Hillary, the Chief Information Security Officer of Drata, to discuss governance, risk, and compliance (GRC) and trust management. They explore key topics such as the evolution of GRC, trust management, compliance automation, and the advent of AI in compliance processes. Matt shares insights on building a world-class GRC program, the challenges and opportunities in modern-day compliance, and the mental health aspects of being a cybersecurity leader. This episode is a must-watch for any cybersecurity professional looking to enhance their GRC strategies and compliance operations.

    Big Thanks to our Sponsor Drata. You can learn more about them at https://drata.com/

    Connect with Matt Hillary at https://www.linkedin.com/in/matthewhillary/

    Transcripts - https://docs.google.com/document/d/1VzRQSEvgUwenDERlNn2bwlIpnz4QPQ15/

    Chapters

    • 01:39 Meet Matt Hillary: CISO of Drata
    • 06:06 The Evolution of GRC and Trust Management
    • 14:48 Continuous Compliance and Automation
    • 19:26 Compliance as Code: The Future of GRC
    • 22:18 The Importance of Getting It Right the First Time
    • 23:15 Customer Compliance Challenges
    • 24:21 Vendor Risk Management and Trust Building
    • 26:26 Leveraging AI for Compliance and Risk Management
    • 31:43 Evaluating Credibility of Third-Party Evidence
    • 41:09 Common Mistakes in GRC Programs
    • 43:56 Final Thoughts and Industry Call to Action
    Show more Show less
    47 mins
  • #235 - Grey is the New Black (with Ryan Gooler)
    Jun 2 2025

    Join G Mark Hardy at THOTCON in Chicago for an insightful podcast episode on building a successful cybersecurity career. Featuring guest Ryan Gooler, they discuss the non-linear paths to success, the value of mentorship, financial planning, and the importance of continuous learning and adapting. Learn how to navigate career transitions, embrace risks, and find joy in teaching and learning from others in the cybersecurity community.

    Transcripts: https://docs.google.com/document/d/1nsd61mkIWbmIL1qube0-cdqINsDujAVH

    Chapters

    • 00:00 Welcome to THOTCON: Meeting Amazing People
    • 00:26 Introducing Ryan Gooler: A Journey into Cybersecurity
    • 04:09 The Value of Mentorship in Cybersecurity
    • 06:22 Career Management and Setting Goals
    • 09:33 Financial Planning for Cybersecurity Professionals
    • 16:40 Automating Finances and Smart Spending
    • 21:25 Financial Sophistication and Mutual Funds
    • 22:07 Automating Life Tasks
    • 22:41 The Concept of a Finishing Stamp
    • 24:17 Leadership and Delegation in the Navy
    • 26:06 Building and Maintaining Culture
    • 27:21 Surviving Toxic Environments
    • 29:55 Taking Risks and Finding Joy
    • 34:34 Advice for Cybersecurity Careers
    • 39:01 The Importance of Teaching and Learning
    • 40:29 Conclusion and Farewell
    Show more Show less
    41 mins
  • #234 - Model Context Protocol (MCP)
    May 26 2025

    In this episode of CISO Tradecraft, host G Mark Hardy delves into the emerging concept of Model Context Protocol (MCP) and its significance in AI and enterprise security. Launched by Anthropic in November 2024, MCP is designed to standardize how AI systems interact with external data sources and applications. Hardy explores how MCP differs from traditional APIs, its implications for security, and the steps organizations need to take to prepare for its adoption. Key topics include the stateful nature of MCP, security risks such as prompt injection and tool poisoning, and the importance of developing a robust governance framework. By the end of the episode, listeners will have a comprehensive understanding of MCP and practical recommendations for safeguarding their AI-driven workflows.

    Transcripts https://docs.google.com/document/d/1vyfFJgTbsH73CcQhtBBkOfDoTrJYqzl_

    References

    Model Context Protocol specification and security best practices, https://modelcontextprotocol.io ⁠

    Security risks of MCP, https://pillar.security ⁠ ⁠

    MCP security considerations, https://writer.com

    Chapters

    • 00:00 Introduction to Model Context Protocol (MCP)
    • 00:27 Understanding MCP and Its Importance
    • 01:41 How MCP Works and Its Security Implications
    • 04:23 Comparing MCP to Traditional APIs
    • 08:41 MCP Architecture and Security Benefits
    • 12:07 Top Security Risks of MCP
    • 18:00 Implementing Security Controls for MCP
    • 25:00 Governance Framework for MCP
    • 28:03 Future Trends and Strategic Recommendations
    • 30:34 Conclusion and Next Steps
    Show more Show less
    33 mins
adbl_web_global_use_to_activate_webcro805_stickypopup
All stars
Most relevant  
If you are looking to learn how to be a CISO this is your show. It's not a talk show or recent events. It teaches the how for you to become knowledgeable on important cyber topics

Can't get enough

Something went wrong. Please try again in a few minutes.