CISO Series Podcast
CISO Series Podcast

CISO Series Podcast

David Spark, Mike Johnson, and Andy Ellis

Overview
Episodes

Details

Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.

Recent Episodes

I'm Worried That We're Not Worried About the Right Worries With AI
DEC 9, 2025
I'm Worried That We're Not Worried About the Right Worries With AI

All links and images can be found on CISO Series.

This week's episode is hosted by David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining them is their sponsored guest, Danny Jenkins, CEO, ThreatLocker.

In this episode:

  • AI for AI's sake
  • Stop selling, start protecting
  • Stop calling everything sophisticated
  • Least privilege, rebranded

Huge thanks to our sponsor, ThreatLocker

ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.

play-circle icon
39 MIN
You Can't Fall Behind in AI if You Never Start
DEC 2, 2025
You Can't Fall Behind in AI if You Never Start

All links and images can be found on CISO Series.

This week's episode is hosted by me, David Spark, producer of CISO Series, and Mike Johnson, CISO, Rivian. Joining us is John Barrow, CISO, JB Poindexter & Co.

In this episode:

  • Building unicorns, not hunting them
  • Cold War frameworks for modern threats
  • Trading dollars for stories
  • Mirror, mirror on the wall

Huge thanks to our sponsor, Vanta

Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information. A recent IDC analysis found that compliance teams using Vanta are 129% more productive. Get back time to focus on strengthening security and scaling your business at vanta.com/ciso

play-circle icon
35 MIN
Why Architect for Human Error When We Can Make People Feel Really Bad About It?
NOV 25, 2025
Why Architect for Human Error When We Can Make People Feel Really Bad About It?

All links and images can be found on CISO Series.

This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis (@csoandy), principal of Duha. Joining them is Richard Rushing, CISO, Motorola Mobility.

In this episode

  • Mindset over tools
  • When hygiene becomes risk
  • Systems for actual humans
  • Conversations over compliance

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® Defense Against Configurations continuously scans endpoints to uncover misconfigurations, weak firewall rules, and risky settings that weaken defenses. With compliance mapping, daily updates, and actionable remediation in one dashboard, it streamlines hardening, reduces attack surfaces, and strengthens security. Learn more at threatlocker.com.
play-circle icon
39 MIN
Are You Implying This Line Graph Isn't a Compelling Cybersecurity Narrative?
NOV 18, 2025
Are You Implying This Line Graph Isn't a Compelling Cybersecurity Narrative?

All links and images can be found on CISO Series.

This week's episode is hosted by David Spark, producer of CISO Series and Andy Ellis (@csoandy), principal of Duha. Joining them is our sponsored guest, Nathan Hunstad, director, security, Vanta.

In this episode:

  • Metrics that matter
  • Testing for real
  • AI as an assistant
  • Intelligence without context

Huge thanks to our sponsor, Vanta

Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information. A recent IDC analysis found that compliance teams using Vanta are 129% more productive. Get back time to focus on strengthening security and scaling your business at vanta.com/ciso

play-circle icon
41 MIN
Our CISO Certainly Puts the Tool in Multi-Tool (LIVE in LA)
NOV 11, 2025
Our CISO Certainly Puts the Tool in Multi-Tool (LIVE in LA)

All links and images can be found on CISO Series.

This week's episode is hosted by David Spark, producer of CISO Series and Jeff Steadman, deputy CISO, Corning Incorporated. Joining them is Quincey Collins, CSO, Sheppard Mullin. This episode was recorded live at the ISSA LA Summit in Santa Monica, California.

In this episode:

  • The foundational debate
  • Strength over breadth
  • Beyond traditional backgrounds
  • Keeping perspective on risk

Huge thanks to our sponsors, Adaptive Security and Dropzone AI

AI-powered social engineering threats like deepfake voice calls, GenAI phishing, and vishing attacks are evolving fast. Adaptive helps security leaders get ahead with an AI-native platform that simulates realistic genAI attacks, and delivers expert-vetted security awareness training — all in one unified solution. Learn more at adaptivesecurity.com.

Dropzone AI autonomously investigates every security alert—no playbooks needed. This AI SOC analyst queries your CrowdStrike, Splunk, threat intel feeds, and 60+ other tools to build complete investigations in 5 minutes. Unlike black-box automation, it shows every query, finding, and decision. See it work yourself—explore the self-guided demo at dropzone.ai.

play-circle icon
45 MIN