CISO Tradecraft® cover art

CISO Tradecraft®

CISO Tradecraft®

By: G Mark Hardy & Ross Young
Listen for free

About this listen

You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level.

© Copyright 2025, National Security Corporation. All Rights Reserved

© Copyright 2025, National Security Corporation. All Rights Reserved
Career Success Economics
Episodes
  • #281 - SIEM Secrets They Don’t Tell You (with Anton Chuvakin & Alex Hurtado)
    Apr 27 2026

    In this CISO Tradecraft episode, host G Mark Hardy talks with Anton Chuvakin and Alex Hurtado about how SIEM programs fail and how organizations overspend when implementations prioritize dashboards or compliance over actionable detection engineering and collecting the right data. They share costly war stories ranging from multi-million and eight-figure deployments that became expensive “log toilets” or missed incidents due to data rationing and gaps, to mid-market teams burned by next-gen startup SIEMs going end-of-life and forcing replatforming. The discussion covers why Gartner Magic Quadrants can be useful depending on organizational context, the tradeoffs of decoupled/hybrid SIEM and security data lake architectures (cost, coverage, vendor management, and real-time detection limits), migration and egress/lock-in concerns, emerging AI/agentic SOC models and pricing, and the need to define requirements and measure effectiveness with realistic detection testing metrics.

    Show More Show Less
    48 mins
  • #280 - Mythos and the Future of Vulnerability Operations (with Gadi Evron)
    Apr 20 2026

    In this episode of CISO Tradecraft, host G Mark Hardy speaks with Gadi Evron about the paper “The AI Vulnerability Storm Building: A Mythos Ready Security Program,” a community-driven draft produced in days with extensive input from security leaders. Evron explains how advances in LLMs and agents are accelerating vulnerability discovery and exploitation, shrinking time-to-exploit assumptions and likely increasing the volume of real vulnerability reports and patches. They discuss separating hype from real risk, the impact of Anthropic’s Mythos and limited access via Project Glasswing, and what CISOs should do now: adopt agents to operate at machine speed, use them defensively to find issues, build “vuln ops” capabilities, secure coding agents in the enterprise, and communicate shifting risk metrics to boards. They also preview the next Unprompted conference planned for September.

    VulnAxis - https://vulnaxis.com/

    Gadi Evron - https://www.linkedin.com/in/gadievron/

    Knostic - https://www.knostic.ai/

    The AI Vulnerability Storm Paper - https://labs.cloudsecurityalliance.org/mythos-ciso/

    Unprompted - https://unpromptedcon.org/

    Show More Show Less
    44 mins
  • #279 - AI Readiness (with JP Bourget)
    Apr 13 2026

    On CISO Tradecraft, host G Mark Hardy welcomes back JP Bourgeet to discuss what “AI readiness” means for organizations, framing it as both a data governance challenge and a change-management problem. JP defines readiness for CISOs as strong threat protection, data security/governance, and device management, with the biggest gaps typically in labeling, DLP/DSPM, and poor information architecture (e.g., commingled data in SharePoint/Drive). They cover re-architecting past and future data into role-based structures so Copilot can honor permissions and sensitivity labels, plus the value of visibility, auditability, and insider-risk alerting for file access and LLM prompts. JP also discusses agentic systems and upcoming identity challenges for AI agents, compares AI readiness to platform engineering, emphasizes use-case-driven adoption (lunch-and-learns and ROI tracking), and highlights Daniel Miessler’s personal AI infrastructure work and a future shift toward AI-driven security products.

    JP Bourget's Website https://www.bluecycle.net/

    JP Bourget's Linkedin https://www.linkedin.com/in/jpbourget/

    SaltCon- https://naclcon.com/

    Show More Show Less
    44 mins
No reviews yet