Find partners
The Virtual CISO Moment

The Virtual CISO Moment

Hosted by Greg Schaffer

TechnologyInterviews guests

Episodes

530

Latest episode

Jun 2026

Language

EN

About the show

The Virtual CISO Moment dives into the stories of information security, information technology, and risk management pros; what drives them and what makes them successful while helping small and midsized business (SMB) security needs. No frills, no glamour, no transparent whiteboard text, no complex graphics, and no script - just honest discussion of SMB information security risk issues. Brought to you by vCISO Services, LLC, a leading provider of vCISO and information security risk management services. Visit https://vcisoservices.com to learn more. A Second Chance Publishing, LLC podcast.

Listen to episodes

60 recent
June 30, 202632 min

S8E25 - From Help Desk to Enterprise Security with Travis Stein

In this episode of The Virtual CISO Moment , Greg Schaffer welcomes Travis Stein, a security engineer whose journey from IT help desk to leading enterprise security programs offers valuable lessons for cybersecurity professionals at every stage of their careers. Travis shares how burnout led him to pursue cybersecurity, why a strong IT foundation remains invaluable, and how networking on LinkedIn opened doors that traditional job searching could not. The conversation also explores leading security as a team of one, transitioning from technical expert to leader, and practical strategies for avoiding burnout while building a rewarding career. Whether you're looking to break into cybersecurity or grow into a leadership role, this episode is packed with practical advice and real-world insights from someone who has successfully navigated both paths.

June 23, 202633 min

S8E24 - Andrew Kalat: What Cybersecurity Can Learn from Aviation

In this episode of The Virtual CISO Moment , Greg Schaffer welcomes cybersecurity veteran, consultant, author, podcaster, and private pilot Andrew Kalat for a wide-ranging discussion spanning more than three decades in information security. Andrew shares his journey from the early days of bulletin board systems and managed security services to leadership roles at organizations including Check Point, U.S. Bank, and SalesLoft, along with the lessons learned from both successes and failures along the way. The conversation takes an unexpected and fascinating turn into aviation, as Greg and Andrew explore the many parallels between flying and cybersecurity. Together, they discuss risk management, incident response, checklists, decision-making under pressure, and what the cybersecurity profession can learn from aviation's mature safety culture. They also examine the realities of security leadership, the challenges of sharing lessons learned from breaches, the importance of preparation before a crisis occurs, and the ongoing struggle to maintain balance and avoid burnout in a demanding profession. Whether you're a security practitioner, consultant, aspiring CISO, or simply interested in leadership and risk, this episode offers practical insights and thoughtful perspectives from a seasoned industry leader who has spent decades helping organizations navigate cybersecurity challenges.

June 16, 202632 min

S8E23 - Bruno Lecoq on AI, CMMC, and SMB Security

In this episode of The Virtual CISO Moment , Greg Schaffer welcomes Bruno Lecoq, Co-Founder, CEO, and CISO of BEMO, for a wide-ranging conversation on Microsoft's evolving security ecosystem, CMMC compliance, and the realities of securing small and midsized businesses. Drawing on nearly two decades at Microsoft and years leading an award-winning cybersecurity firm, Bruno shares insights on the rapid pace of AI innovation, why SMBs must carefully vet their technology partners, and the hidden risks organizations face when pursuing compliance without truly embracing security. The discussion also explores CMMC requirements, Microsoft security capabilities, and the importance of building trust-based relationships with clients. Bruno also reflects on his remarkable journey from France to Microsoft, the future of AI governance, and how a lifelong passion for football (soccer) helps him stay balanced in an ever-changing industry. A thoughtful conversation packed with practical advice for cybersecurity leaders, MSPs, and business executives alike.

June 9, 202639 min

S8E22- Alan Clinard Discusses Building Security Programs That Actually Work

In S8E22, Greg Schaffer sits down with Alan Clinard, founder of Athena vCISO Services, to explore what it really means to be a trusted security advisor. Drawing from a career that spans the U.S. Army, operational risk consulting, banking, critical infrastructure, and virtual CISO services, Alan shares how understanding the business—not just the technology—is the key to effective cybersecurity leadership. The conversation dives into translating cyber risk into business language, the challenges of moving from technical expert to consultant, and why humility and relationship-building are often more important than technical knowledge when influencing organizations. Alan also discusses entrepreneurship, mentoring the next generation of security leaders, and helping clients become self-sufficient rather than dependent on outside advisors. Whether you're a security practitioner aspiring to leadership, a current vCISO, or a business executive trying to bridge the gap between security and business objectives, this episode offers practical insights on governance, risk management, consulting, and building security programs that truly support organizational success.

June 2, 202636 min

S8E21 – Cy Sturdivant on Community Banking, Risk, and Cyber Leadership

Cy Sturdivant returns to the Virtual CISO Moment to share lessons from more than two decades in cybersecurity, financial services, and consulting. The conversation explores the importance of professional relationships, security program maturity, AI adoption in banking, and why organizations that focus solely on compliance often struggle to improve their overall security posture. Cy also discusses the concept of TEA—Time, Energy, and Attention —and why protecting these limited resources is critical for long-term success in both cybersecurity and life. Along the way, he offers practical advice for professionals looking to grow their careers, adapt to constant change, and maintain balance in a demanding industry. If you're a cybersecurity leader, aspiring consultant, community banking professional, or simply looking for practical advice on balancing career success with personal fulfillment, this episode offers actionable insights, thoughtful perspective, and plenty of wisdom from someone who has spent decades helping organizations navigate risk and change.

May 28, 202633 min

S8E20 – Becky MacDonald on Building Security Beyond Compliance

In this episode of The Virtual CISO Moment , Greg Schaffer sits down with cybersecurity leader and Cyber Risk Navigator founder Becky MacDonald to discuss the evolution of cybersecurity leadership, the realities of virtual CISO work, and why effective security programs must be built around risk—not just compliance checklists. Drawing from decades of experience across healthcare, higher education, and nonprofit organizations, Becky shares practical insights into building mature cybersecurity programs with limited budgets, communicating risk to leadership, and avoiding common traps like tool sprawl and “checkbox security.” Greg and Becky also explore the growing virtual CISO space, including what separates strong vCISO leadership from superficial security consulting. The conversation covers the importance of business communication skills, balancing technical and strategic perspectives, and the challenges organizations face when trying to operationalize security in real-world environments. Becky also offers candid perspectives on entrepreneurship, cybersecurity burnout, and the realities of building a boutique advisory practice. Whether you are an aspiring vCISO, a cybersecurity practitioner, or a business leader trying to better understand risk and resilience, this episode delivers practical insights grounded in real-world experience.

May 19, 202635 min

S8E19 - Cybersecurity, Community, and Leadership with Jonathan Weaver

In this episode of The Virtual CISO Moment , Greg Schaffer sits down with Jonathan Weaver to discuss the evolving role of governance, risk, and compliance in today’s cybersecurity landscape. Jonathan shares his journey from the University of Tennessee into cybersecurity consulting, the lessons he learned building ProInsight, and why trust and relationships are often the most valuable assets in security consulting. The conversation also explores practical risk management, the challenges organizations face in understanding cybersecurity beyond compliance checklists, and the importance of breaking down silos between business and security teams. Beyond cybersecurity, Jonathan opens up about his nonprofit initiative, Reindeer for Hope, which provides gifts and support to underprivileged children and families across Middle Tennessee. Listeners should tune in for an insightful mix of cybersecurity leadership, entrepreneurship, community impact, and personal perspective from someone who is passionate about helping both organizations and people become more resilient.

May 12, 202637 min

S8E18 – Why Identity Is the Future of Cybersecurity with Jackie Shoback

In this episode, Jackie Shoback—Co-Founder of 1414 Ventures and seasoned C-suite leader—joins Greg to explore how cybersecurity has evolved from a back-office IT function into a core business strategy. Drawing on decades of experience across enterprise and financial services, Jackie breaks down why digital identity and trust are now at the center of modern security , and how organizations must rethink data as both an asset and a risk. The conversation dives into the growing importance of identity-driven security, the shortcomings of current privacy practices, and the role of boards and executives in building a true culture of security—not just checking compliance boxes. With insights on emerging threats, AI, and the future of digital trust, this episode offers a strategic lens for leaders navigating today’s rapidly evolving cyber landscape.

May 5, 202626 min

S8E17 - Mid TN ISACA Conference Chats

At the 2026 Middle Tennessee ISACA conference I had the chance to sit down for short chats with a few information security pros: India James, who spoke on the importance of security and digital trust at the conference; Ken Smith, Director of Sales Engineering Enterprise for the Great Lakes at Arctic Wolf; and Jonathan Weaver, Partner at ProNsight's Risk and Compliance Consulting Practice.

April 30, 202631 min

S8E16 - Real-World CMMC Insights with Rich Bates

Rich Bates shares a candid look at his 30+ year journey into cybersecurity, from early computing days to leading GRC programs and now building his own advisory practice focused on helping organizations tackle CMMC and compliance challenges. Along the way, he breaks down why these frameworks matter, the real risks businesses face if they ignore them, and how to approach security in a practical, business-focused way. Listeners will get valuable insights into navigating regulatory complexity, making smart risk decisions, and what it really takes to succeed as a cybersecurity leader or consultant. Whether you're a business owner facing CMMC requirements or a security professional looking to sharpen your approach, this episode offers real-world perspective without the fluff

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts