
CISO Series
David Spark
Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.
Recent Episodes
We Strongly Value Your Willingness to Accept Less
Sep 15, 2026Gina Ciavarro, former managing director of infrastructure and CISO at Accordion, discusses evolving vulnerability management frameworks like SSVC, the problematic hiring market for first-time CSOs, the importance of pre-incident decision rights and incident command structures, and architectural security challenges posed by AI-driven development. The episode covers patching strategies, CVSS limitations, board-level risk acceptance, and detecting system decay versus superficial health.
Backlogs? Where We're Going We Don't Need Backlogs.
Sep 8, 2026Varsha Agrawal, Head of Information Security at Prosper Marketplace, discusses critical challenges in modern security leadership including vendor lock-in with AI tools, board governance failures, and how AI should reshape security team capabilities. The episode examines the tension between business speed and security controls, the need for boards to make conscious risk decisions rather than rely on traffic-light dashboards, and what security teams should actually be optimizing for when time is no longer the constraint.
When Frameworks Stop Being Polite and Start Getting Real
Sep 1, 2026Ryan Brown, Director and Head of Cybersecurity Operations at Children's National Hospital, discusses the gap between written security policy and actual clinical workflow. The episode explores how compliance frameworks and audits fail to surface real-world operational challenges, using healthcare examples like credential sharing and password practices. Brown advocates for security leaders to conduct on-site "ride-alongs" to understand how staff actually work under pressure, arguing that policies nobody can follow at the bedside are confessions of never visiting the bedside.
"Ignorance Is Bliss" Is Our Acceptable Use Policy
Aug 25, 2026Rob Allen, Chief Product Officer at ThreatLocker, joins host David Spark and co-host Edward Contreras (CISO, Frost Bank) to discuss vulnerability management delegation, shadow AI and acceptable use policies, the Mac vs. Windows security debate, and hiring for problem-solving ability rather than credentials. The episode challenges conventional cybersecurity wisdom across detection vs. prevention, policy enforcement vs. control, and the role of imagination in talent acquisition.
Secure by Design. Ignored by Default.
Aug 18, 2026Julie Davila, president of Security Tinkerers, discusses how security must shift from a culture problem to a structural one. She challenges the assumption that secure code alone prevents incidents, drawing on examples from GitLab and her startup experience to argue that context matters more than best practices, and that security scales through strategic investment in automation and architecture rather than headcount alone.
Why Solve Your Problems When We Can Just Scare You?
Aug 11, 2026Nada Noaman, SVP and CISO of Estée Lauder Companies, joins hosts David Spark and Mike Johnson (CISO, Rivian) to discuss critical security challenges in the AI era. The episode explores how organizations can balance AI automation with the apprenticeship model needed to develop future security leaders, manage non-human identities and privilege access without defaulting accountability to the CISO, shift from vulnerability finding to remediation, and build behavioral security programs that constrain user power while enabling safe experimentation.
See, Our Compliance Framework Includes a Checkbox for Resilience
Aug 4, 2026Khush Kashyap, Senior Director of GRC at Vanta, joins David Spark and Mike Johnson (CISO, Rivian) to discuss security team resilience, risk quantification beyond dollar amounts, and the future of AI-driven compliance frameworks. The episode challenges traditional compliance-first approaches, exploring how security posture should drive compliance as a byproduct rather than the inverse, and examines practical paths to automating GRC work without burning out teams.
Why Don't You Tell Me Which Metrics Sound Most Impressive?
Jul 28, 2026Pavi Ramamurthi, Global CSO and CIO at Blackhawk Network, joins the CSO Series to discuss vanity metrics in security, the perverse incentives in SIEM and compliance reporting, and the Delve audit scandal. The episode explores how security leaders balance political necessity with honest risk communication, the theater of SOC 2 compliance, and the flaws in third-party risk management questionnaires.
With AI, I Can Now Be Pulled in 5x More Directions at Once!
Jul 21, 2026Terry Daniel, Principal at Udia, joins David Spark and Andy Ellis to discuss how AI is transforming security work—multiplying tasks and cognitive load rather than simply lightening workloads. The episode explores burnout risks in security teams, the gap between stated security culture and actual employee behavior, the dangers of LLMs reinforcing leadership blind spots, and how organizational trust directly impacts insider risk programs and employee loyalty.
ClickLock's kill loops, TELEPUZ ClickFix tricks, 1Password's agentic login
Jul 17, 2026
Show artwork and metadata belong to the publisher and are shown here editorially, as part of documenting the corpus behind our analyses. Inclusion does not imply any endorsement of, or by, Parsed Analytics.