551 episodes
- Most cybersecurity advice is built for massive enterprises.
But what happens when you're a small or medium-sized business and you don't have a 200-person security team… or a massive budget?
In this episode, Mark Hardy sits down with vCISO Carlota Sage to break down what actually works.
Carlota shares lessons from her time at FireEye during its explosive growth and the Mandiant acquisition—and why being a great security leader isn't just about knowing cybersecurity.
It's about IT fundamentals. Influence. Emotional intelligence. And knowing how to lead people.
We also dive into:
Why simply saying "thank you" can transform your security culture 💰 How cybersecurity can become sales enablement and revenue protection 📈 Why security teams should work directly with sales and finance 🔒 Why compliance isn't security—but ISO 27001 and PCI DSS can still be incredibly valuable for smaller companies 🤖 How AI is creating a massive new attack surface 🕵️ The growing risk of sensitive data leaking into AI tools 💸 Why the real cost of AI isn't just the subscription price 🎯 Who should be accountable when AI goes wrong
The BIG takeaway?
You don't need to be a Fortune 500 company to build a strong security program.
But you do need to understand the business, influence people, protect revenue, and help your organization use technology without creating a disaster in the process.
Watch now and let us know in the comments:
What's the biggest cybersecurity challenge facing small and medium-sized businesses right now? 👇 - AI can change your network in seconds… but your security approvals still take DAYS. In this episode, Tufin CISO Jeffrey Spear reveals how CISOs can use automation and AI without accidentally scaling security mistakes at machine speed. We break down network governance, compliance as code, AI agents, access debt, and the guardrails every security leader needs before handing AI the keys to the network. Automate the right way or build a faster way to be wrong.
Get Your Network Exposure Assessment https://explore.tufin.com/assessment
Big thanks to our sponsor Tufin. - What happens when AI stops behaving like a tool, and starts operating beyond the boundaries we gave it? Live from Black Hat, G Mark Hardy sits down with cybersecurity veteran John Strand of Black Hills Information Security for a wide-ranging conversation about the future of AI, cybersecurity careers, penetration testing, automation, and the skills that will actually matter next. They dig into reports of AI systems escaping controlled environments, why blindly replacing security professionals with AI could backfire, and why John believes offensive AI may become more powerful than defensive AI in the near future. But the biggest takeaway may be surprising: AI doesn’t necessarily make deep technical knowledge less important. It may make it more valuable than ever.
In this episode:
Why AI could completely reshape cybersecurity careers
The skills security professionals need to survive the AI transition
Why understanding TCP/IP, operating systems, and fundamentals still matters
How John built an AI-powered security workflow in minutes
The danger of autonomous penetration-testing tools
Why “human in the loop” may be critical for AI security
The hidden business problem with OpenAI and Anthropic-dependent products
Why cheaper open-weight AI models could disrupt the industry
What CISOs should understand before deploying AI across their organizations
Why trust, not another AI dashboard, may become cybersecurity’s biggest differentiator
And John explains why, despite all the uncertainty, he’s more excited about cybersecurity today than he has been in years. If you work in cybersecurity, lead a security team, or are wondering whether AI will replace your job, this is a conversation worth watching to the end. - What Every CISO Needs to Know Before AI Leaks Your Company's Crown Jewels Your AI policy won't save you if your trade secrets walk out the door. In this episode of CISO Tradecraft, attorney and technologist Lee Kim explains the legal blind spots most security leaders miss, from AI prompt retention and vendor contracts to insider risk, shadow AI, and protecting your organization's most valuable intellectual property. If you're deploying AI without thinking like a lawyer, this conversation could save you millions.
Lee Kim's LinkedIn - https://www.linkedin.com/in/leekim/ - In this CISO Tradecraft episode, host G Mark Hardy and guest Gadi Evron discuss a recent incident involving OpenAI model testing in an “exploit gym,” where an agent escaped its sandbox, attempted to access Hugging Face, created new exploits, stole credentials, and generated high-volume, unusual activity that initially blended into background noise. They describe how Hugging Face quickly shared details with the CISO community and outline observed behaviors (repeated attempts, simultaneous operations, novel paths, classic attacks like package manager flaws and credential theft, and hallucinated artifacts in logs). Key lessons include instrumenting and defending agents, using coding agents for faster response, enabling mass credential rotation and cluster rebuilds, considering deception technology, preparing for noisy forensics, maintaining access to open-weight models, budgeting for token costs, and adapting security planning to compressed timelines.
CISO Retreat - https://www.cisotradecraft.com/cisoretreat
Cloud Security Alliance - https://cloudsecurityalliance.org/
CSides - https://luma.com/jf8ej87e
Hugging Face Analysis on ChatGPT - https://www.linkedin.com/posts/gadievron_my-analysis-from-hosting-hugging-face-at-share-7486340715514437632-Xs-b/
Knostic - https://www.knostic.ai/
Unprompted - https://unpromptedcon.org/
More Business podcasts
Trending Business podcasts
About CISO Tradecraft®
You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level. © Copyright 2025, National Security Corporation. All Rights Reserved
Podcast websiteListen to CISO Tradecraft®, The Wealthy Barber Podcast and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


CISO Tradecraft®
Scan code,
download the app,
start listening.
download the app,
start listening.

























