Page de couverture de The New CISO

The New CISO

The New CISO

Auteur(s): Steve Moore
Écouter gratuitement

À propos de cet audio

The New CISO is hosted by Exabeam Chief Security Strategist, Steve Moore. A former IT security leader himself, Steve sits down with Chief Information Security Officers to get their take on cybersecurity trends, what it takes to lead security teams and how things are changing in today’s world.517748 Économie
Épisodes
  • The Four Cs: Why a Schoolteacher Makes a Great CISO
    Jan 29 2026

    In this episode of The New CISO, host Steve Moore speaks with Manuel "Manu" Ressel, CISO at SAUTER Group, about his unconventional journey from classroom teacher to cybersecurity leader—and why the "Four Cs" of modern education provide a powerful framework for building effective security programs. Drawing from years as both a teacher and school principal in Germany, Manu introduces Critical Thinking, Communication, Collaboration, and Creativity as essential leadership skills that fundamentally challenge how the industry approaches awareness training and incident response.

    After growing frustrated with Germany's outdated education system that prioritized memorization over critical thinking, Manu left his position as principal and reinvented himself as a digital transformation consultant. Working with schools and mid-sized companies to adopt cloud technologies, he eventually landed the CISO role at SAUTER, an international building automation company with 4,000 employees across multiple countries.

    The conversation tackles security's most persistent failure: awareness training that doesn't work. Manu reveals that 37% of security incidents in Germany could be prevented if users made better decisions, yet most organizations rely on boring click-through programs. He advocates for scenario-based, role-specific training—an approach now mandated by Europe's NIS 2 regulation—that treats people as the biggest opportunity in cybersecurity rather than the weakest link.

    One of the episode's most practical frameworks is Manu's Observation-Description-Interpretation method for analyzing security incidents. He explains how humans naturally jump from observation directly to interpretation, skipping the crucial middle step of accurately describing what actually happened. This leads to finger-pointing, misdiagnosis, and hasty decisions. By training security analysts to pause and describe incidents factually first, teams make better decisions and build trust with the business.

    Manu challenges the punitive approach many organizations take toward security failures, particularly companies that fire employees for repeatedly clicking phishing simulations. He champions building positive fault cultures where employees feel safe reporting mistakes. His three crisis questions—Is anyone dying? Major financial impact? Will someone be hurt?—provide a simple framework for staying calm and deciding when immediate action is necessary versus taking time to think strategically.

    Key Topics Discussed:

    1. Why the "Four Cs" (Critical Thinking, Communication, Collaboration, Creativity) define effective security leadership
    2. The Observation-Description-Interpretation framework for incident analysis without bias
    3. Transforming ineffective awareness training into engaging, scenario-based programs
    4. Building positive security cultures where employees report issues without fear
    5. NIS 2's mandate for role-specific cybersecurity training across organizational levels
    6. Why Germany and European mid-market companies lag in cloud adoption
    7. Three critical crisis questions: Is anyone dying? Financial impact? Risk of harm?
    8. Why punitive phishing training destroys trust and cultural engagement
    9. Applying teacher skills to security leadership and de-escalation...
    Voir plus Voir moins
    54 min
  • Safety Third: Why Security Shouldn't Be Your Top Priority
    Jan 8 2026

    In this episode of The New CISO, host Steve Moore speaks with Alex Rice, Founder, CTO, and CISO at HackerOne, about challenging one of cybersecurity's most deeply held beliefs—that security should be the top priority. Drawing from his journey building security programs at Facebook and founding HackerOne, Alex introduces the "safety third" philosophy and explains why accepting that security is never first can actually make you more effective as a leader.

    Alex shares his unconventional path into cybersecurity, starting as a 14-year-old programmer in rural Florida and eventually leading product security at Facebook during its explosive growth. He reveals how Facebook ran 70+ penetration tests annually with top-tier vendors and still wasn't finding enough vulnerabilities—until they opened the doors to the hacker community and received over 300 valid findings in a single weekend. This experience became the foundation for HackerOne's bug bounty platform.

    The conversation tackles critical leadership challenges facing modern CISOs, including the toxic tendency toward victim blaming when breaches occur, why security teams struggle with customer-centric design, and how to avoid becoming the team everyone knows only for blocking work and sending phishing tests. Alex argues that security professionals must stop drinking their own Kool-Aid and recognize that usability and business outcomes will always take precedence over security controls.

    In the episode's second half, Alex addresses AI's role in security operations with refreshing pragmatism. Rather than chasing grandiose AI visions, he advocates for starting with narrow, well-defined tasks where agents can replace security toil—like automated CVSS scoring or vulnerability triage—building trust and expertise before tackling more ambitious projects. He warns against the current trend of AI tools that find more problems when security teams desperately need help fixing the mountain of issues they already know about.

    Alex also challenges CISOs to stop over-owning problems like asset inventory management that rightfully belong to other executives, emphasizing the importance of cross-functional collaboration over building security-owned solutions that ultimately fail. Throughout the discussion, he champions a philosophy of empathy, customer-centricity, and accepting hard truths about security's actual place in business priorities—a mindset shift that paradoxically makes security leaders far more effective.

    Key Topics Discussed:

    1. Why "safety third" should be every CISO's operating philosophy
    2. The problem with victim blaming in cybersecurity incidents
    3. Building customer-centric security programs that enable rather than block
    4. Lessons from scaling Facebook's security program with 70 pen tests per year
    5. The origin story of HackerOne and crowdsourced security testing
    6. How to avoid becoming the security team everyone resents
    7. Practical AI implementation: Starting with toil elimination, not transformation
    8. Why CISOs over-own asset management and other problems
    9. The importance of process mapping before deploying AI agents
    10. Aligning security teams closely with AI and software...
    Voir plus Voir moins
    1 h et 7 min
  • Just Starting in Security? Here’s What You Need to Succeed
    Dec 4 2025

    In this episode of The New CISO, host Steve Moore speaks with Iain Paterson, Chief Information Security Officer at Well Health Technologies, about his unconventional path into cybersecurity and the lessons learned from building programs across industries—from banking and healthcare to breach response and beyond.

    From skipping college to take an eight-month technical boot camp to leading enterprise security programs, Iain shares how curiosity, hands-on experience, and communication skills shaped his journey. He opens up about the realities of hiring in cybersecurity, why foundational IT work still matters, and how soft skills like empathy and composure are essential for effective leadership. Iain also reflects on leading through high-stress incidents, including the Ashley Madison breach, and explains why staying calm, communicating clearly, and maintaining emotional intelligence define the “new CISO.”

    Key Topics Covered:

    • A nontraditional start: skipping college for certifications and hands-on learning
    • Why technical foundations—servers, networks, and support—still matter
    • The problem with “boilerplate” resumes and lack of real-world experience
    • Why soft skills are a security superpower: communication, patience, and empathy
    • Transitioning from technician to business enabler in cybersecurity
    • How early help desk experience builds composure and problem-solving ability
    • Lessons from running vulnerability management in large-scale banking
    • Learning resilience and resourcefulness as a one-person security team in healthcare
    • Behind the scenes of the Ashley Madison breach: stress, responsibility, and empathy
    • Why composure, calm communication, and credibility matter in crisis response
    • The leadership evolution from technical expert to executive decision-maker
    • Building peer networks and finding mentorship to combat isolation as a CISO

    Iain’s story highlights how real experience, emotional intelligence, and community support transform good technologists into exceptional leaders. His insights remind us that cybersecurity isn’t just about defense—it’s about communication, composure, and connection.

    Voir plus Voir moins
    50 min
Pas encore de commentaire