Find partners
Cybersecurity Ecosystem Show

Cybersecurity Ecosystem Show

Hosted by Cybersecurity Ecosystem Show

Episodes

89

Latest episode

Aug 2026

Language

EN

About the show

The Cybersecurity Ecosystem Show connects the full spectrum of the industry: practitioners, investors, vendors, regulators, and everyone in between — because the more we learn from each other, the stronger we become.

Listen to episodes

60 recent
August 20, 202633 min

From the SEC to 25,000 Board Members: Pricing Cyber Risk Like an Insurer

Christopher Hetner has seen the board conversation from every seat: building New York City data centers in the nineties, running global information security at GE Capital, advising two chairs of the SEC as senior policy advisor, and three years inside the insurance industry learning how brokers and carriers actually price cyber exposure. Today he is Chief Cyber Advisor at World Wide Technology, Cyber Risk Advisor to the National Association of Corporate Directors and its roughly 25,000 members, and chair of the AI and Cyber Insights Council for the NASDAQ Center for Board Excellence. In this conversation, Chris and Taylor dig into the numbers behind the board disconnect: roughly 70 percent of directors are still not in tune with how cyber and AI materially impact the business, many CISOs get 20 minutes with the audit committee once a year, and AI has compressed attack reconnaissance from months to minutes. Chris lays out the fix layer by layer. Build an enterprise risk management structure even when no regulator requires it, with a charter, a risk register, and the heads of the business in the room. Quantify exposure with annual loss expectancy analysis benchmarked to your peer group, in the same categories the insurance markets use. Then go the step further that traditional models skip: tell the board where to deploy capital, and trend the exposure down quarter over quarter. Also in here: why the CISO should never report to the board alone, the professionalization problem behind slow risk quantification adoption, treating AI agents like employees who commit agent error, and why post-quantum readiness has to start now. If you present to a board, sit on one, or want to someday, this episode is a masterclass. Chris's path: NYC data centers, GE Capital global CISO, senior policy advisor at the SEC Why sophisticated boards still struggle: business lens, not bits and bytes The 70 percent problem and governing on 20-year-old assumptions Reconnaissance compressed from three or four months to minutes The isolated CISO: M&A blind spots, inflated budgets, reactive posture Building enterprise risk management without a regulatory mandate Charters, risk registers, and the COSO framework Reporting in tandem with the CFO, chief risk officer, and heads of business Annual loss expectancy analysis and the insurance markets as the ultimate arbiter Peer group benchmarks: why pharma, hospitals, and trading platforms all look different Going beyond FAIR: substantiating loss and directing capital "A language that we understand": what changes for the board Why cyber risk quantification adoption is still low, and the tactical CISO problem Culture and tone from the top AI agents as employees, agent error, and agentic-to-agentic monitoring Q-day and starting post-quantum readiness now Christopher (Cristobal) Hetner is the Chief Cyber Advisor at World Wide Technology, Cyber Risk Advisor to the National Association of Corporate Directors, and chair of the AI and Cyber Insights Council for the NASDAQ Center for Board Excellence. His nearly 30 years in cyber and technology include building data centers in New York City, serving as global CISO at GE Capital, four years as senior policy advisor to two chairs of the SEC, and three years working with major insurance brokers and carriers on sizing cyber exposure. He also advises the Cyber Future Foundation and engages roughly a dozen boards a year as an independent expert. Chris on LinkedIn: Christopher Hetner

August 6, 202635 min

Private Equity Speed, Shadow AI, and the Middle Layer Everyone Skips

Kevin Lewis has a political science degree, a career that started while he was waiting to hear back from the NYPD, and a job today that puts him inside a stack of companies at once. He is the CISO at E78 Partners, a boutique consulting firm serving small and mid-size private equity funds and their portfolio companies, where he also sits in fractional CIO and CTO seats for clients, most of them in med spa and healthcare. In this conversation, Kevin and Taylor get into why the industry's biggest win is that security stopped being the department of no, how to translate risk for a CFO who has already decided what security should cost, and what private equity's two-day definition of "fast" teaches you about scoping honestly. Kevin walks through the AI reporting pilot that pulled 15 systems into one data lake and replaced a week-long report request with a real-time answer. Then the harder stuff: why he thinks the talent shortage is partly a spending decision, why he does not tolerate gatekeeping on his team, what he actually screens for when he reads every resume himself, and why the network is the middle layer most career-changers skip. He closes with the culture playbook, including the reframe worth stealing: phishing simulation results measure how well the security team communicated, not how bad the employees are. Whether you run a program, advise one, or are trying to break into the industry, this one is full of things you can use on Monday. What's working in security: the shift from "no, you can't" to "let's make this work" Why the seat at the table matters for the information, not the title Selling to a CFO: the daily cost of zero work, remediation, and reputation Security dashboards with business metrics attached What private equity's timeline teaches you about honest scoping The AI pilot: 15 systems, one data lake, and an agent that builds the KPI report Why mentoring faded, and why Kevin requires it from his leads Gatekeeping, the scarcity mindset, and the tools-instead-of-people trap Hiring without certification or degree requirements The network: the middle layer between "no computer experience" and "security analyst" Why "we're not a target" is the sentence that makes you one Security awareness without fear, and phishing as a metric on your own team Responsiveness as the real control for shadow IT and shadow AI Retiring a rogue tool without making an enemy Kevin Lewis is the CISO at E78 Partners, a boutique consulting firm that works at the intersection of the CEO, CFO, and CIO for private equity funds and their portfolio companies. Alongside running E78's internal security program, he takes fractional technology leadership roles with client companies and handles pre-close technology due diligence for PE deals. His career spans a DOD contractor, fashion and apparel, and now consulting across whatever industry walks in the door, which suits him: to Kevin, it's all bits and bytes. He holds a master's in cybersecurity and a bachelor's in political science, came up through help desk and networking, and mentors relentlessly because that is how he got in. Kevin on LinkedIn: Kevin Lewis Email: klewis@e78partners.com E78 Partners: e78partners.com

July 17, 202643 min

The Dark Knight of Game Economies on AI, Curiosity, and Guardrails

Ward Spangenberg has spent his career finding the gaps: mapping trout DNA with a homemade database in college, dismantling a game economy's black market so thoroughly that players nicknamed him the Dark Knight, and helping build the case for bug bounties at HackerOne. Now he's the founder of Behavry.ai, building in the category Gartner calls guardian agents. In this conversation, Ward and Taylor dig into why security spends its money explaining last night instead of preventing tomorrow, what purple teaming should have become, how to hire engineers with the play instinct, and why AI won't take over but ungoverned agents absolutely will hurt you. Ward breaks down the four things real AI agent governance requires: no self-attestation, real-time review of every action, human-in-the-loop escalation instead of binary yes/no decisions, and tamper-evident audit trails that regulators are about to start asking for. Whether you're a practitioner, a founder, an investor, or just AI-curious, this one is full of stories you'll retell. What's acutely broken in security: an industry built on hindsight Thinking like an attacker: every door, every window, one unlocked Purple teaming as a quarterly exercise when you don't have the budget Hiring for curiosity: role-play interviews and the "what do you play with at home" question Why AI won't take over (and why it doesn't write perfect code) The junior analyst who becomes a level two with the right AI tooling Ward's origin stories: trout genetics, game fraud, and the Dark Knight Why you can't kill the black market: the bug bounty lesson Behavry.ai and the guardian agents category: proxy, policy, attestation The compliance wave: EU AI rules, Wyoming, and the SEC Ward Spangenberg is a longtime security practitioner and leader whose career spans companies like Uber, HackerOne, and a Silicon Valley gaming company, plus years presenting to lawyers and law enforcement investigators. He is the founder of Behavry.ai, an AI governance platform that adds policy, human-in-the-loop controls, and independent, tamper-evident attestation to any AI agent, model, or provider. He is also a rugby coach, a gym rat, and the kind of person who stuck a paper clip in an outlet as a kid and grew up to build guardrails for a living. Behavry.ai Ward on LinkedIn: Ward Spangenberg Ward on Twitter/X: @wardspan

June 11, 202633 min

Shift Left, Real Moats, and Where Your Data Actually Goes, with Chris Bollerud

Most security leaders come up through IT or risk. Chris Bollerud came up through code, and it changes how he sees the entire field. Chris is the CISO at AppZen, an AI-driven finance platform, and a software engineer of more than twenty years before that. In this episode he explains why AI gives attackers and defenders the same speed boost, why shifting left only works when you automate the catch instead of training developers and hoping, and how a single dinner with two competing vendors reframed his view of application security. From there the conversation widens out. Chris makes the case that third party risk management is overdue for a reset, that frameworks like ISO 42001 and the NIST AI RMF have not earned enterprise trust, and that nearly every security questionnaire reduces to one question: where does my data go. He also shares the one line from an early career review that reshaped how he communicates, why he thinks AI slop is the next propaganda problem, and what makes a real moat when a buyer can rebuild most of your tool in weeks. A wide-ranging conversation for anyone in or around cybersecurity, from practitioners and vendors to investors and regulators. Listen and follow so you don't miss what's next.

May 28, 202634 min

Line Cook to CISO: Eric Freeman on AI, Access Control, and Why Security Is Just Dinner Prep

Eric Freeman is the CISO at Writer, an AI-native company that has built its own large language model. Before that, he worked across blockchain and emerging technology. Before any of that, he was a line cook pulling 16-hour shifts in a restaurant kitchen six days a week. That background shows up in everything about how he leads. In this episode, Eric draws a direct line between prepping for dinner service and implementing security controls, between reading a plate and reading a log, between surviving a Friday night rush and surviving a major incident. We get into how AI is changing both offense and defense in cybersecurity right now, with specific examples of how his team is using LLMs to automate vulnerability validation end-to-end. He explains why context is the only thing that makes AI useful and shares a learning framework where team members use personal analogies to internalize unfamiliar concepts through LLMs. Eric also doesn't hold back on what's broken. He makes the case that cybersecurity stress is a structural problem, not a personal one, and proposes a mandatory security credit score for businesses. He breaks down prompt injection as social engineering for machines, agents as scripts with more dynamicness, and reduces all of cybersecurity to a single mental model: access control. We close with his framework for the three camps of cybersecurity buyers, why two of those camps are the reason the industry still sells on fear, and how to build a security culture with engineers by making the secure path the fastest path. For practitioners, vendors, investors, and anyone trying to understand how the cybersecurity industry actually works underneath the noise. Connect with Eric Freeman on LinkedIn: https://www.linkedin.com/in/eric-m-freeman/

May 14, 202628 min

Data Governance, Board Buy-In, and the Thing You Can't Shut Off: A CISO's Cross-Industry Playbook

Janet Heins has led cybersecurity programs in pharma, manufacturing, cruise lines, broadcast media, and healthcare. Every industry felt unique from the inside, and they are. But the patterns she's found underneath are what make this conversation worth listening to. Every industry has a system that can't be shut off, even when security demands it. Every organization has legacy infrastructure that's too embedded to replace and too old to protect with modern tools. And almost no company has a dedicated leader responsible for governing the data that everything else depends on. In this episode, Janet walks through what she's learned moving across industries by design. She shares the four-category framework she uses to get board buy-in for cybersecurity investments: operational, financial, reputational, and regulatory. She explains why aligning security to the company's mission is the difference between being seen as the department that says no and being treated as a strategic partner. And she gets into why data governance is the gap that's making every other cybersecurity and AI challenge harder than it needs to be. We also talk about AI and what it means for practitioners right now, why university cybersecurity curricula are struggling to keep pace, what major security incidents actually feel like from the inside, and what Janet learned writing her book Go Ahead, Ask For It about making your value visible and advancing your career. This one is for CISOs who want a framework they can use in any industry, practitioners thinking about career growth, vendors who want to understand how security leaders actually make decisions, and investors trying to evaluate security maturity from the outside. Connect with Janet Heins on LinkedIn: https://www.linkedin.com/in/janetheins/ Get Go Ahead, Ask For It on Amazon: https://www.amazon.com/Go-Ahead-Ask-Value-Undeniable-ebook/dp/B0GLR2W4D5

April 30, 202632 min

OEM Partnerships: What Every Practitioner, Vendor, and Investor Needs to Understand

The threat intel in your SIEM, the scanning engine in your endpoint tool, the analysis powering your detection platform. There's a good chance those capabilities come from a company you've never directly evaluated. That's OEM. And it touches every corner of cybersecurity. Chad Loeven has spent 20 years building OEM partnerships on both sides of the table, licensing technology inbound as a buyer and outbound as a seller. In this episode, he breaks open one of the most misunderstood parts of the cybersecurity market and explains how it actually works. We get into what qualifies as OEM versus resale or MSSP, why OEM can be the smartest go-to-market path for startups, and the real stories behind deals that worked and deals that didn't. Chad shares the seven-figure Yahoo contract that nearly drained his company, the DLP product that proved some solutions just don't OEM well, and the time he walked into a company where 25% of revenue disappeared overnight because of a single OEM dependency. But this isn't just a conversation for partnership teams. If you're a practitioner, this episode explains why some capabilities in your stack feel native and others feel bolted on. It's about your vendors' partner ecosystems and why they matter to your security posture. If you're an investor, Chad breaks down why OEM revenue gets discounted, when that discount is justified, and the concentration risk questions you should be asking during due diligence. If you're a vendor, you'll walk away with a framework for which products OEM well, how to structure deals that don't erode your margins, and why technology integrations are the front door to your best OEM relationships. OEM is the invisible infrastructure underneath most of the cybersecurity products the industry depends on. This conversation makes it visible.

April 21, 202632 min

Code War: How Nations Hack, Spy & Shape the Digital Battlefield — Allie Mellen on Cybersecurity’s Geopolitical Evolution

Explore the ever-evolving digital battlefield on the Cybersecurity Ecosystem Show as we connect the dots between nations, history, and the future of cyber conflict. In this episode, Allie Mellen discusses her new book on how the United States, China, and Russia leverage hacking and information operations to shape global security and power. From the impact of multi-domain warfare in the Gulf War to Russia's cyber experimentation in Ukraine, Allie Mellen unpacks nation-state motivations, social contracts, and what every sector—from practitioners to investors, vendors, and regulators—needs to understand about the present and future of cyberwarfare. Join us as we bridge history, technology, and practical insights for the entire cybersecurity community.

December 6, 202538 min

Unlocking Sales Engineering Excellence in Cybersecurity: Best Practices, Trends & Impact

Join Taylor Wells, Tony Kelly, and Justin Bauer on this insightful episode of Security Revenue LIVE as they dive deep into the evolving role of sales engineers in the cybersecurity space. Discover why sales engineers are key to connecting the dots between technical solutions and real business outcomes, and how they can advocate for customers while influencing product development, marketing, and customer success across the organization. Packed with practical advice and real-world stories, this episode explores best practices for building and scaling SE teams, driving effective customer engagement during the pre-sales process, and executing impactful POCs and workshops. Whether you’re a go-to-market leader, aspiring SE, or curious about the intersection of technical expertise and sales success, you’ll leave with actionable strategies to elevate your approach and drive impact in the fast-paced world of cybersecurity. Tune in for expert perspectives, audience Q&A, and the inside scoop on what works, what doesn’t, and what’s next for technical sales leaders!

October 30, 202547 min

How Top Cyber Companies Win with Customer Success in 2025

Customer Success sits at the center of cybersecurity go-to-market growth . Joy Aaring, David Tirazona, and Julie Giannini share real-world strategies for transforming CS from a post-sales function into a true driver of revenue, expansion, and advocacy. Learn how top teams accelerate time to value, strengthen customer relationships, and build authentic advocacy — even in a market where privacy is paramount.

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Business podcasts