
Security Leadership Essentials for Managers
mnemonic security podcast
07/11/22
•39m
About
Comments
Featured In
Security leadership essentials for managers
What knowledge base should a CISO have? And what is the best approach to shaping the next generation of security leaders?
Our guest today is better equipped than most to answer these questions. Frank Kim, former CISO of and currently a Fellow and Curriculum Director at SANS Institute, joins Robby to discuss leadership essentials for security managers.
Frank shares how SANS and their classes approach teaching strategic leadership in security, and how this can help CISOs both navigate the politics in the boardroom and craft a business plan that makes sense for their entire organisation.
They also discuss to whom security ultimately report to, and how to lead, motivate and inspire security teams to get their work done.
Sound engineering by Paul Jæger
Previous Episode

Zero Trust vs. Castle and Moat
June 27, 2022
•44m
Zero trust vs. castle and the moat
What does zero trust have to do with electric cars?
For this episode, Robby is joined by Tony Fergusson CISO – EMEA at Zscaler. Tony has more than 25 years of experience in IT networking and security in Manufacturing, Information Technology and Financial Services, and even more importantly, he loves talking about zero trust – and has done so for more than a decade.
Tony chats with Robby about his article “What IT can learn from Tesla about disrupting the status quo”, and why he believes the zero trust security model represents "an elegantly simple" path forward. They also talk about what the biggest obstacles to the zero trust model are, and why he thinks some people and companies are scared of the zero trust concept.
Related reading: “Stop trying to make firewalls happen: What IT can learn from Tesla about disrupting the status quo“ https://revolutionaries.zscaler.com/insights/stop-trying-make-firewalls-happen-what-it-can-learn-tesla-about-disrupting-status-quo
Sound engineering by Paul Jæger
Next Episode

TIBER
August 8, 2022
•37m
Threat Intelligence-Based Ethical Red-teaming
In most organisations, there’s more to security than preventive measures. This means that testing your capabilities within detection, investigation and containment can be just as relevant as looking at preventive capabilities. One way of doing so, is by following the Threat Intelligence Based Ethical Red-teaming (TIBER) framework, and simulating a real adversary and how you organisation would do against such a threat.
To explain how a TIBER test is performed and it’s most common use-cases, Robby is joined by Stan Hegt, Etical hacker, Red teamer and Co-founder of the Dutch security company Outflank. Stan also shares his observations of the evolution of red teaming, the main differences between pentesting and red teaming, and what challenges they often meet when preforming these tests.
A special thanks to Dennis Nuijens at Cqure for helping us to find our guest for this episode!
Sound engineering by Paul Jæger
If you like this episode you’ll love
Promoted




