Nach Genre filtern

Cyber Smokehouse

Cyber Smokehouse

TBDCyber

This is Cyber Smokehouse. Join Ernie and Graeme as they grill the minds, dig into the experience, and serve up the stories of leaders in cybersecurity. Cyber Smokehouse is sponsored by TBDCyber, a cybersecurity strategy consulting firm.

29 - Agentic Development and the Evolution of DevSecOps - Ken Toler - Cyber Smokehouse - Episode #28
0:00 / 0:00
1x
  • 29 - Agentic Development and the Evolution of DevSecOps - Ken Toler - Cyber Smokehouse - Episode #28

    Take your application security strategy to the next level with powerful insights on securing fast-paced agentic development, navigating abstracted SaaS platforms, and bridging the gap between engineers and security teams. It’s time to move past rigid no-saying, embrace "vibe coding" as a shared collaborative workspace, and build resilient security systems that stand the test of time. Who better to guide you through it than DevSecOps podcast host, blockchain application security expert, and Founder & Managing Principal Consultant at Asgard Security, Ken Toler?

    You will learn how AI-driven tools are accelerating threat modeling and supply chain management, why abstracted "squishy middle" infrastructure presents new attack vectors, and how to foster a curious, error-friendly engineering culture. Get motivated to enable your developers, simplify system abstractions, and build collaborative bridges across your entire organization!

    Takeaways:

    The Pace of Agentic Development: AI tools and agentic development aren't changing core security fundamentals; rather, they are accelerating execution and making practices like threat modeling and supply chain fixes faster to implement.Preserving Systems Thinking: While AI lowers barriers to coding, engineers and security teams must still maintain deep reading and architectural comprehension to diagnose complex system vulnerabilities.The Danger of the "Squishy Middle": Modern abstracted platforms (like Replit or Lovable) consolidate credentials and environment variables into shared SaaS infrastructure, creating lucrative targets for attackers.Embracing Citizen Developers & "Vibe Coding": When non-technical departments prototype apps using AI, security and engineering teams should engage collaboratively rather than dismissively to build organizational alignment.Enabling Over Blocking: Security leaders thrive by finding creative, positive ways to enable business goals securely instead of being the transactional "no guy".

    Quote of the Show:

    "I've gotten so much further figuring out how to enable people securely rather than trying to tell people why they are insecure. Nobody wants to talk to the angry security guy." - Ken Toler


    Links:

    X: RelotnekLinkedIn: https://www.linkedin.com/in/kentoler/Website: https://www.asgardsec.com


    Ways to Tune In:


    Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
    Tue, 15 Sep 2026
  • 28 - Building Security Programs from the Ground Up - Eddie Younker - Cyber Smokehouse - Episode #27

    Take your cybersecurity program to the next level with powerful insights on structuring security reporting lines, combating shadow risk, and building an engaged, transparent team culture from scratch. It’s time to move past organizational blind spots, establish top-down AI guardrails, and align vulnerability management directly with business priorities. Who better to guide you through it than Fortune 100 security leader, former CISO at Hyundai Capital America, and former VP & CISO at LIV Golf, Eddie Younker?

    You will learn how reporting directly to executive leadership eliminates conflicts of interest, why effective vulnerability management relies on business support rather than just IT execution, and how to foster a "family away from family" culture that achieves industry-leading employee engagement. Get motivated to build cross-functional relationships, educate leadership teams, and take a business-first approach to security!

    Takeaways:

    The Power of Reporting Structure: Reporting directly to the CEO gives security leaders the visibility and authority needed to embed security into operational processes, whereas reporting under a CTO can create conflict between speed-to-market and risk management.Mitigating Shadow IT and AI Risks: Emerging tools and ad-hoc AI adoption create shadow risk across organizations; mitigating this requires clear corporate guardrails, top-down governance, and strong cross-departmental relationships.Business-Centric Vulnerability Management: Successfully patching high-priority vulnerabilities isn't just an IT task, it requires educating business stakeholders, managing tech debt, and securing executive buy-in to prevent operational downtime.Transparent and Inclusive Leadership: High-performing security teams are built on transparency, mutual respect, and hiring for complementary skill sets rather than redundant backgrounds.Practical Advice for Rising Security Leaders: Gaining broad experience across multiple security domains gives rising professionals the holistic perspective needed to apply security frameworks to real-world business environments.

    Quote of the Show

    "Building a security culture starts with the reporting structure... You need a structure that enables you to own security for the entire organization and drive governance that gets support from the business." - Eddie Younker\


    Links:

    LinkedIn: https://www.linkedin.com/in/eddie-younker-19559a96/Website: https://www.livgolf.com/


    Ways to Tune In:


    Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
    Tue, 08 Sep 2026
  • 27 - Protecting Delivery and Outcomes - Chris Logan - Cyber Smokehouse - Episode #26

    Take your cybersecurity strategy to the next level with powerful insights on securing modern healthcare delivery, bridging the digital divide, and translating complex security tech into executive business language. It’s time to rethink patient care availability, move beyond legacy castle-and-moat models, and adopt platform-based zero trust architectures. Who better to guide you through it than U.S. Marine Corps veteran, published author, and Healthcare CISO at Zscaler, Chris Logan?

    You will learn how ambient AI is transforming clinical workflows, why health systems must consolidate point solutions into platform security to speed up M&A, and how servant leadership builds resilient, high-performing security teams. Get motivated to speak the language of business executives, protect critical patient care environments, and open career doors for the next generation of cyber leaders!

    Takeaways:

    Securing Care Everywhere: Healthcare has shifted from hospital-centric care to decentralized delivery across home, mobile, and wearable devices, making system availability vital to preventing negative patient outcomes.Leading with Business Outcomes Over Tech: Security leaders must frame investments in terms of clinical continuity, patient care, and revenue impact rather than technical jargon to win CFO and board support.The Rise of Ambient AI in Clinics: Ambient AI listening tools are relieving clinicians of manual EMR documentation during visits, restoring eye contact and the human relationship between doctor and patient.Platform Consolidation vs. Point Solution Noise: Health systems need platform-based security and the "80/20 rule" to reduce software sprawl, cut costs, and shorten clinic onboarding times from 18 months down to weeks.Servant Leadership & "Good Leaders Eat Last": True cyber leadership requires approachability, conducting skip-level check-ins, allowing teams room to fail forward, and opening doors for others to grow.

    Quote of the Show:

    "If you lead with technology when speaking to your board or CFO, you've already failed. They don't care about the technology, they care about the business outcome." - Chris Logan

    Links:

    LinkedIn: https://www.linkedin.com/in/logancm/Website: https://www.zscaler.comEmail: clogan@zscaler.com  christopherm.logan@gmail.com 


    Ways to Tune In:


    Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
    Tue, 01 Sep 2026
  • 26 - Retiring from Risk - Scott Barronton - Cyber Smokehouse - Episode #25

    Take your understanding of cybersecurity risk, organizational alignment, and executive career pivots to the next level with powerful insights from a 30-year industry veteran! It’s time to rethink the evolving personal liability of CISOs, how to effectively communicate cyber risk to non-technical business leaders, and what it really takes to walk away and build a successful second-act venture. Who better to guide you through it than former CISO at Finastra and Diebold Nixdorf, and co-founder and Chief Travel Officer at Sunshine Travelers Experiences, Scott Berrington?

    In this episode, you will learn how the rapid influx of emerging tech like AI creates mounting operational risk, the pros and cons of different CISO reporting structures, and strategies for providing true security assurance to demanding global clients. Get motivated to build empowered, self-sufficient security teams, navigate executive burnout, and turn your lifelong passions into your next big career milestone!

    Takeaways:

    The Shifting Risk-Reward Matrix for CISOs: Increasing personal and criminal liability for CISOs, coupled with 24/7/365 operational burnout, is causing many seasoned security leaders to rethink the CISO role.Emerging Tech & AI Disruption: Business leaders often adopt fast-moving technologies like AI for efficiency without fully understanding the rapid, potent risks involved, leaving CISOs to clean up structural mistakes.Optimal Security Reporting Lines: Security functions operate best when reporting to a Chief Risk Officer or Chief Legal Officer due to shared risk frameworks, whereas reporting to a CIO or CFO often introduces budget and operational friction.Proactive Customer Assurance: Rather than waiting for demanding enterprise clients to audit your environment, presenting a comprehensive, tailored security program builds deep customer trust and streamlines compliance.Delegation with Accountability: Effective leadership means giving direct reports full authority to execute while keeping a "quick hook" offline to coach them gently without destroying their internal credibility.

    Quote of the Show:

    “I was proud when I got my first CISO role, but there’s no type of pride like being an entrepreneur and taking that role of trying to build something from scratch.” - Scott Barronton


    Links:

    LinkedIn: https://www.linkedin.com/in/scottbarronton/   https://www.linkedin.com/company/sunshine-travelers-experiences/home/Website: https://www.sunshinetravelersexperiences.com/Podcast Link: https://podcasts.apple.com/us/podcast/sunshine-travelers-podcast/id1683937797


    Ways to Tune In:


    Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
    Tue, 25 Aug 2026
  • 25 - Identity, Patching, and Zero-Downtime Security - Keith Lawson - Cyber Smokehouse - Episode #24

    Take your cybersecurity operations to the next level with powerful insights on managing high-volume vulnerability patches, securing healthcare IT/OT environments, and applying deep reinforcement learning to autonomous defense. It’s time to move beyond reactive security measures and build resilient, zero-downtime systems in live, life-safety environments. Who better to guide you through it than healthcare CISO, critical infrastructure veteran, and University of Michigan-Dearborn researcher, Keith Lawson?

    You will learn how the surge in AI coding agents is driving a "tsunami" of software patches, strategies for managing identity as the modern perimeter, and how autonomous AI agents can adapt in real time to protect critical infrastructure. Get motivated to foster a zero-blame, collaborative culture that empowers your technical and non-technical teams to solve complex security challenges together.

    Takeaways:

    The Vulnerability Tsunami: The adoption of AI coding agents by software vendors is generating a massive wave of bug fixes and corresponding exploits, requiring organizations to automate testing and speed up patching cycles.Identity as the Modern Perimeter: As healthcare and enterprise data shift to cloud and SaaS environments, human vulnerabilities and weak identity controls, rather than traditional network perimeters, have become the primary target for social engineering and exploitation.Zero-Downtime Patching in Healthcare: Securing complex hospital networks (spanning medical IoT, legacy software, and life-critical devices) requires strict pre-planning, automated testing, and a zero-tolerance approach for service disruptions.Applied Reinforcement Learning: Unlike static large language models (LLMs), reinforcement learning enables real-time, continuous online learning for autonomous cyber defense against zero-day threats.Fostering a Zero-Blame Culture: Effective security leadership relies on open collaboration, empowering staff across all departments, and maintaining a transparent, zero-blame environment so teams can report mistakes and fix root causes fast.

    Quote of the Show:

    "In security, I think open honesty and sharing is the best thing that we can do... To me, security is a team sport." - Keith Lawson


    Links:

    LinkedIn: https://www.linkedin.com/in/j-keith-lawson/Website: blog.9600baud.net http://www.lhsc.on.ca


    Ways to Tune In:


    Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0 Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297 Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47 iHeart Radio: https://iheart.com/podcast/319629841/ Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
    Tue, 18 Aug 2026
Weitere Folgen anzeigen