Find partners
Defense in Depth

Defense in Depth

Hosted by CISO Series

TechnologyNewsInterviews guests

Episodes

370

Latest episode

Aug 2026

Language

EN

About the show

Defense in Depth, hosted by David Spark, Steve Zalewski, Geoff Belknap, and Edward Contreras, promises clear talk on cybersecurity's most controversial and confusing debates. Once a week we choose one controversial and popular cybersecurity debate and use the InfoSec community's insights to lead our discussion.

Listen to episodes

60 recent
August 13, 202631 min

What Makes a Good AI Security Deployment?

What Makes a Good AI Security Deployment? All links and images can be found on CISO Series Check out this post by Chris Matthews of UpGuard for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Peter Liebert, CISO, Salesloft & Clari. In this episode: Non-determinism changes everything The foundation problem Nobody owns the whole problem The authorization gap A huge thanks to our sponsor, CoreView Attackers don't break into Microsoft 365. They log in and reconfigure it. When tenant configurations drift or get tampered with, recovery can take weeks and missed settings can reopen the door. The Cyber Resilience Framework for Microsoft 365 covers the five pillars, harden, govern, detect, respond, recover, and shows exactly where today's tools leave gaps. Download the free practical guide

August 6, 202628 min

The Office Politics of Remediation

All links and images can be found on CISO Series Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Dan Walsh, CISO, Datavant. Joining is our sponsored guest, Elizabeth Nammour, founder and CEO, Teleskope. In this episode: Data ownership before automation A shared vocabulary for agent risk Maturing from crawl to run Trust earns automation its place A huge thanks to our sponsor, Teleskope Most DSPMs stop at finding the risk. Teleskope fixes this: it automatically finds sensitive data, including IP documents or board decks, and remediates exposure across cloud, SaaS, and AI environments natively, with human-in-the-loop controls, improving your team's efficiency tenfold. Trusted by Ramp, Polymarket, and Chevron Phillips, and more. teleskope.ai

July 30, 202630 min

Why is Preventative Security So Difficult?

All links and images can be found on CISO Series Prevention in cybersecurity is a lot like flossing: everyone knows they should do it, but few do it enough. What's stopping us? Check out this post by Ross Haleliuk of Venture in Security for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Deneen DeFiore, vice president & chief information security officer, United Airlines. In this episode: The sponsorship gap One strike and you're out Policy without position Prevention isn't static A huge thanks to our sponsor, CoreView Attackers don't break into Microsoft 365. They log in and reconfigure it. When tenant configurations drift or get tampered with, recovery can take weeks and missed settings can reopen the door. The Cyber Resilience Framework for Microsoft 365 covers the five pillars, harden, govern, detect, respond, recover, and shows exactly where today's tools leave gaps. Download the free practical guide

July 23, 202630 min

Identity and Access Management (IAM) in an Agentic AI World

All links and images can be found on CISO Series Check out this post by Tomás Maldonado, CISO, NFL, for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Yaron Levi, CISO, Dolby. Joining is Will Gregorian, vp of information technology & security, Galileo Medical. In this episode: From who to what The manipulation problem Cryptographic accountability The audit gap A huge thanks to our sponsor, ActiveState ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time. Learn more at ActiveState.com.

July 16, 202633 min

Protecting AI Agents in O365 and Google Workspace

All links and images can be found on CISO Series Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining is their sponsored guest, Rajan Kapoor, vp, security, Material Security. In this episode: Pre-existing conditions Architecture over rollout Access isn't legitimacy Data has a half-life A huge thanks to our sponsor, Material Security Legacy email security only watches the door. Material protects your entire cloud workspace—email, files, and accounts—as one ecosystem. It's more coverage for less than the cost of a legacy SEG. One price, no surprises: just security that covers the whole surface area. Learn more at material.security.

July 9, 202635 min

Humans Are Bottleneck in a Machine-Speed World

All links and images can be found on CISO Series We're evolving fast to secure AI. But are we evolving fast enough to secure WITH AI? Check out this post by Rinki Sethi, CSO, Upwind Security, for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Howard Holton, former CEO, GigaOm. Joining is Adam Glick, CSO, PSG Equity. In this episode: Human-in-the-loop math Should machines decide at all From assistant to autonomous Redefining the security role A huge thanks to our sponsor, Palo Alto Networks   Cortex Cloud unifies code, cloud, and SOC on a single data, risk, and control plane — giving teams the context, workflows, and agentic intelligence to turn risk into resolution. Native AI agents investigate and act within enterprise guardrails, delivering real-time protection from workload to network edge. Cloud security that outpaces machine-speed threats. Visit paloaltonetworks.com/cortex/cloud.

July 2, 202633 min

Even With All These Security Vendors We Still Have Glaring Gaps

All links and images can be found on CISO Series There are thousands of cybersecurity vendors across categories. If there's a gap in the market, it's likely not for technical reasons. So, how do you actually find vendors that are a good fit rather than one that just meets technical requirements? Check out this post by Joe Head of REFLEX Solutions for the discussion that is the basis of our conversation on this week's episode, co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Ajit Girn, CIO, Employment Development Department (EDD). In this episode: Built for vendors, not users Signal versus noise Priced out The elegance gap A huge thanks to our sponsor, ThreatLocker ThreatLocker takes a deny-by-default approach to endpoint security — controlling what applications can run, what can access data, and what can elevate privileges. Used by organizations that want to reduce attack surface without relying on detection alone. Learn more at threatlocker.com/ciso.

June 25, 202627 min

Is the "Attackers Only Need to Be Right Once" a Misnomer?

All links and images can be found on CISO Series Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and George Finney, CISO, University of Texas System. Joining is Sean Walls, CISO, Bob's Discount Furniture. In this episode: Asymmetric accounting Sometimes it really is that easy The spirit of the saying The cheapest way in A huge thanks to our sponsor, Native Security Native is the Cloud Security Control Plane. It helps enterprises enforce secure-by-design architecture across multi-cloud environments by translating security intent into the cloud provider's built-in controls, previewing impact before rollout, and keeping enforcement aligned as the environment changes.

June 18, 202655 min

What It Takes To Be Successful in Cyber Media

What It Takes To Be Successful in Cyber Media All links and images can be found on CISO Series Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Dave Bittner, producer and host, The CyberWire. Joining is Graham Cluley, host of Smashing Security podcast and Leo Laporte, founder of TWiT (This Week in Tech) and host of Security Now podcast. In this episode: Format follows function The decision gap Practitioner fingerprints Beyond the news cycle A huge thanks to our sponsor, Palo Alto Networks Cortex Cloud unifies code, cloud, and SOC on a single data, risk, and control plane — giving teams the context, workflows, and agentic intelligence to turn risk into resolution. Native AI agents investigate and act within enterprise guardrails, delivering real-time protection from workload to network edge. Cloud security that outpaces machine-speed threats. Learn more at paloaltonetworks.com/cortex/cloud/demo.

June 11, 202631 min

CISOs Buy For Selfish and Politically Risk-Averse Reasons (Not Because Your Product is the Best)

All links and images can be found on CISO Series Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Howard Holton, CEO, GigaOm. Joining is Tyler King, senior director - threat operations and response, Sinclair. In this episode: Career insurance In the trenches together Who are you actually selling to? Common sense, uncommon in sales A huge thanks to our sponsor, Material Security Legacy email security only watches the door. Material protects your entire cloud workspace—email, files, and accounts—as one ecosystem. It's more coverage for less than the cost of a legacy SEG. One price, no surprises: just security that covers the whole surface area. Learn more at material.security.

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts