CISO Series Podcast (Live)

BSidesSF 2024 · Day 1

Overview

This article details a live recording of the popular CISO Series podcast, held at BSidesSF 2024. Hosted by David Spark, with co-host Mike Johnson (CEO of Rivian) and special guest Steve Zooki (host of "Defense and Depth"), the session offered a candid and often humorous exploration of critical issues facing cybersecurity professionals today. The discussion spanned a diverse range of topics, from the evolving landscape of open source software licensing and the unique pressures experienced by CISOs, to the challenges of cybersecurity hiring and the imperative for sales teams to articulate tangible business value.

Watch on YouTube

Visual summary for CISO Series Podcast (Live)
Visual summary for CISO Series Podcast (Live)

Key moments

  1. 05:00 Open source licensing changes (Redis) and the 'Golden Goose' risk.
  2. 07:00 Legal and liability concerns driving open source licensing changes.
  3. 10:00 CISO challenges: M&A without security involvement, incident reporting to the board.
  4. 27:00 Critique of bad cybersecurity hiring practices and effective interview techniques.
  5. 32:00 Expectations for cybersecurity sales teams and aligning security to business value.
  6. 40:00 Risk perception: APT vs. NSA attack.
  7. 43:00 Operationalizing S-BOMs and current state efficacy.

CISO Series Podcast (Live)

Speakers: Unknown

Conference: BSidesSF 2024

YouTube: https://www.youtube.com/watch?v=UvnEIad8Pu4

Overview

This article details a live recording of the popular CISO Series podcast, held at BSidesSF 2024. Hosted by David Spark, with co-host Mike Johnson (CEO of Rivian) and special guest Steve Zooki (host of "Defense and Depth"), the session offered a candid and often humorous exploration of critical issues facing cybersecurity professionals today. The discussion spanned a diverse range of topics, from the evolving landscape of open source software licensing and the unique pressures experienced by CISOs, to the challenges of cybersecurity hiring and the imperative for sales teams to articulate tangible business value.

The live podcast format, recorded in front of an engaged audience, fostered a dynamic and "community-driven" atmosphere, as described by the speakers. Unlike traditional technical presentations, this session focused on real-world experiences, strategic considerations, and the human element within cybersecurity. It provided valuable insights into the strategic thinking of seasoned security leaders, offering perspectives on how to navigate complex technical, business, and interpersonal challenges in the ever-changing threat landscape.

The talk is particularly relevant for cybersecurity leaders, aspiring CISOs, and anyone interested in the strategic and operational aspects of managing security programs. It highlights the importance of adaptability, critical thinking, and effective communication in a field where technical expertise must be seamlessly integrated with business acumen. The conversational style allowed for a deeper dive into the "why" behind certain industry trends and challenges, making it a compelling listen for professionals seeking to understand the broader context of their work.

Background

▶ Watch: Open source licensing changes (Redis) and the 'Golden Goose' risk. (05:00)

The live CISO Series podcast recording took place at BSidesSF 2024, an event characterized by its "community-driven" nature, a stark contrast to the more commercially focused RSA Conference that often follows it. Speakers Mike Johnson and Steve Zooki emphasized that BSides fosters "real conversations" among peers, often in a more relaxed, "t-shirts and no socks" environment, as Steve Zooki humorously put it. This setting provided an ideal backdrop for the CISO Series, which aims to deliver "the most fun you'll have in cybersecurity" while tackling serious topics.

The CISO Series itself is a well-established media network for cybersecurity professionals, with David Spark serving as its host and producer. Mike Johnson has been a co-host for nearly six years, bringing his perspective as the CEO of Rivian to the discussions. Steve Zooki, a veteran CISO and host of the "Defense and Depth" show, joined as a guest, contributing his extensive experience, particularly from his time at Levi Strauss.

The problems discussed during the podcast are perennial challenges within the cybersecurity industry. The debate around open source licensing, exemplified by Redis's recent changes, reflects an ongoing tension between the open source ethos of free modification and distribution, and the commercial realities of sustaining development and support for widely used projects. This issue has historical precedents, such as the fork of Elastic Search that led to Elastic Cash, indicating a recurring pattern in the industry.

Similarly, the "Confessions of a CISO" segment addressed the immense pressure and unique fears faced by security leaders. These fears, ranging from unexpected board meetings to unconsulted management decisions on acquisitions or cloud provider changes, highlight the CISO's often precarious position at the intersection of technical risk and business strategy. The discussion underscored the need for CISOs to maintain composure and strategic communication, even when facing significant internal and external pressures.

The segment on "What's broken about cybersecurity hiring" delved into the frustrations associated with ineffective interview practices, such as reliance on trivia questions or binary answers for senior roles. This reflects a broader industry struggle to accurately assess candidates' critical thinking and problem-solving abilities, rather than just their rote knowledge. Finally, the discussion on "cybersecurity sales" addressed the persistent gap between sales teams' product knowledge and CISOs' need for solutions that clearly articulate business value, a common point of friction in vendor-client relationships. These topics collectively underscore the complex, multi-faceted nature of cybersecurity leadership and operations in today's environment.

Key Findings

▶ Watch: CISO challenges: M&A without security involvement, incident reporting to the ... (10:00)

The live CISO Series podcast unearthed several critical findings and insights across various domains of cybersecurity, reflecting the real-world challenges and strategic considerations of security leaders.

1. The Evolving Landscape of Open Source Licensing:

The discussion highlighted a significant trend in the open source community, exemplified by Redis changing its in-memory database licensing. This change restricts developers from building off or modifying the code, though auditing remains permissible. Speakers noted that Redis is not the first to implement such changes, citing the historical example of Elasticsearch and its fork, Elastic Cash.

  • Drivers: The primary driver for these changes is often revenue generation, necessary to fund support services. However, Steve Zooki introduced a "creative thinking" perspective, suggesting that legal and third-party/fourth-party risk management concerns might also play a role, as lawyers seek to mitigate liability issues arising from open source usage.
  • Impact: Mike Johnson posited that "big companies really are going to be fine with this," as they will either license the software if they see value or fork it if the new terms are unacceptable. The consensus was that this trend represents a "bump in the road" rather than "killing the Golden Goose" of open source, suggesting continued adaptation within the ecosystem.

2. The Unique Pressures and Fears of a CISO:

CISOs, often perceived as "cool under pressure," face specific scenarios that can cause significant stress. Popular responses from the cybersecurity subreddit, echoed by the speakers, included:

  • Emergency board meetings with little notice.
  • Management decisions made without CISO consultation, such as acquisitions lacking a risk assessment or unannounced changes in cloud providers.
  • The emergence of new regulations that could lead to legal accountability for CISOs.
  • Steve Zooki specifically cited being excluded from M&A (Mergers & Acquisitions) discussions as a major source of disrespect and subsequent defensive posture. He also detailed the increased workload and political navigation required when an incident escalates to the board, involving PR teams, legal counsel, and board secretaries. Mike Johnson emphasized the importance of maintaining composure and trust, acting as a "therapist" or "lawyer" for their teams, even while acknowledging the need for private stress release.

3. Addressing Dysfunctional Cybersecurity Hiring Practices:

The podcast critically examined common flaws in cybersecurity hiring, particularly for senior positions.

  • Bad Interview Questions: A common complaint was the prevalence of "trivia questions" or requests for simple "yes or no" answers without context, which fail to assess true expertise.
  • Standardization vs. Relevance: Mike Johnson argued for asking the same questions to all candidates (junior to senior) to enable fair comparison, but stressed that these questions must be well-designed. He cited his own experience being asked "What is the number of TCP ports?" as an example of a useless trivia question, contrasting it with "What is the number of bricks in Brazil?" which, while difficult, revealed critical thinking.
  • "What's Worse" Scenarios: Mike highlighted the utility of "what's worse" scenarios in interviews, as they reveal on-the-spot critical thinking and, crucially, the candidate's ability to explain their reasoning.
  • Candidate Empowerment: Interviewees were advised to take control of the flow, expanding on even poorly phrased questions to showcase their prowess and critical thinking.
  • Political Realities: Steve Zooki introduced the "political reality" perspective, suggesting that sometimes interview questions are merely procedural, either because the hiring decision has already been made (and the interview is for relationship building) or because the candidate is simply "fodder for the process" to meet a quota.

4. The Imperative for Business-Oriented Cybersecurity Sales:

A significant portion of the discussion focused on the critical gap in knowledge and approach within cybersecurity sales.

  • Knowledge Expectation: Steve Zooki differentiated expectations: junior SDRs using scripts are forgivable, but senior sales professionals must possess a deep understanding of the product and its relevance to enterprise security. He argued that selling security is fundamentally different from selling consumer goods like sneakers.
  • Demonstrating Business Value: Steve's "how does it sell more jeans?" challenge (referencing his time at Levi Strauss) became a central theme. He explained that sales teams must articulate how their solution either makes the security team more efficient (doing more with less) or more effective at stopping attacks, ultimately protecting the brand, people, and supply chain.
  • Consequences of Ignorance: Both speakers agreed that a lack of deep understanding from sales teams can lead CISOs to "write off a company." Mike Johnson added that sales teams should research target companies to anticipate security challenges and bring in technical experts (sales engineers, security architects) when necessary.

These findings collectively paint a picture of a cybersecurity landscape grappling with foundational issues in technology adoption, leadership resilience, talent acquisition, and strategic vendor engagement.

Technical Deep Dive

▶ Watch: Critique of bad cybersecurity hiring practices and effective interview techni... (27:00)

While the CISO Series podcast is primarily a strategic and conversational show, several technical concepts, tools, and industry solutions were discussed, providing a glimpse into the operational realities and challenges faced by cybersecurity professionals.

The most prominent technical discussion revolved around open source licensing changes. The specific example of Redis, an in-memory data structure store, was cited for its decision to alter its licensing model. This change, as described, prevents developers from building off or modifying the code, a significant departure from traditional open source principles, though auditing capabilities remain. This move is not isolated, with Elasticsearch and its commercial entity, Elastic, having previously undergone similar licensing shifts that led to the creation of Elastic Cash as a fork. The underlying technical implication here is the shift from permissive open source licenses (e.g., MIT, Apache) to more restrictive "source-available" licenses that aim to protect commercial interests while still allowing code visibility. This impacts how organizations integrate, maintain, and potentially contribute to these foundational technologies.

Supply chain security emerged as a critical area, with Eclypsium highlighted as a sponsor specializing in this domain for "critical software, firmware, and hardware in Enterprise infrastructure." The mention of Paul Asadorian's webinar, "Unraveling Digital Supply Chain Threats and Risk," and a paper on the relationship between ransomware and the supply chain, underscores the technical complexity and high stakes involved. From a technical perspective, supply chain security involves ensuring the integrity and authenticity of all components, libraries, and services used in an organization's software and hardware stack, from development to deployment. This includes vulnerability management in third-party components, secure development practices by suppliers, and continuous monitoring for compromise.

Related to supply chain integrity, the concept of SBOMs (Software Bill of Materials) was discussed. While recognized as an "aspirational risk management process" and a necessity for the future, its "current state" was deemed "not good" and "difficult to operationalize." The core technical challenge cited was the "Turtles all the way down" problem: an SBOM for a product requires SBOMs from its suppliers, who in turn need SBOMs from their suppliers, creating an exponentially complex dependency chain. For organizations like Rivian, dealing with "four or 500 suppliers that are giving us parts that go into our vehicles," generating and consuming comprehensive, actionable SBOMs is a monumental data management and integration task. The value of SBOMs lies in providing granular visibility into software components, enabling faster identification and remediation of vulnerabilities (e.g., Log4j), but achieving this at scale remains a significant technical hurdle.

Attack surface management was another key area, with NetSpy introduced as a sponsor offering "continuous visibility beyond a pentest" to identify and reduce risk to "known and unknown assets." Technically, this involves automated discovery of internet-facing assets (IP addresses, domains, cloud resources, IoT devices), continuous vulnerability scanning, configuration assessment, and threat intelligence integration to provide an up-to-date view of an organization's external attack surface. This moves beyond periodic, point-in-time assessments to a dynamic, ongoing process crucial for large, distributed environments.

The discussion also touched upon fundamental security operations technologies. Dvo was presented as a sponsor providing a "real-time security data platform powered by hyperstream," which integrates SIM (Security Information and Event Management), SOAR (Security Orchestration, Automation, and Response), and UEBA (User and Entity Behavior Analytics). This platform leverages AI and intelligent automation to enable faster and smarter security operations. Technically, this involves ingesting vast amounts of log data from diverse sources, correlating events to detect threats, automating incident response workflows, and using machine learning to identify anomalous user and entity behaviors that might indicate compromise. The goal is to reduce alert fatigue, accelerate detection, and streamline response.

Finally, a segment involving "Dave's Mom" humorously explored basic cybersecurity terminology, highlighting common misconceptions but also reinforcing core concepts:

  • Insider threat: A malicious or negligent threat from within an organization.
  • Sandboxing: An isolated environment for executing untrusted code safely.
  • Man-in-the-middle (MITM): An attack where an attacker secretly relays and possibly alters the communication between two parties who believe they are directly communicating with each other.
  • Cross-site scripting (XSS): A type of security vulnerability typically found in web applications, enabling attackers to inject client-side scripts into web pages viewed by other users.

These terms, while basic, represent foundational technical knowledge essential for any cybersecurity professional. The discussion, though lighthearted, served to underscore the importance of clear communication and understanding of these concepts, even for non-technical stakeholders.

In summary, while the podcast did not delve into exploit specifics or code snippets, it provided a valuable technical overview of critical industry trends, challenges, and solutions in areas such as open source governance, supply chain integrity, attack surface management, and modern security operations platforms.

Demo / Proof of Concept

▶ Watch: Risk perception: APT vs. NSA attack. (40:00)

The CISO Series Podcast (Live) at BSidesSF 2024 was a conversational panel discussion and did not include any live technical demonstrations or proofs of concept. The format was focused on dialogue, experience sharing, and audience engagement rather than showcasing specific tools or exploits in action. While sponsors like Eclypsium and NetSpy offer product demos, these were not part of the live podcast content.

Defensive Implications

▶ Watch: Operationalizing S-BOMs and current state efficacy. (43:00)

The insights shared during the CISO Series podcast offer several actionable defensive implications for cybersecurity professionals, particularly CISOs and security teams.

  1. Strategic Open Source Management: Given the evolving licensing models (e.g., Redis, Elastic), organizations must adopt a proactive strategy for managing their open source dependencies. This includes:
  • Legal and Risk Assessment: Conduct thorough legal reviews of open source licenses for critical components to understand usage restrictions, especially concerning modification and commercial use. Integrate these assessments into third-party and fourth-party risk management frameworks.
  • Forking and Licensing Strategies: Be prepared to either license commercial versions of open source software or consider forking projects if licensing changes become prohibitive for core business functions. This requires internal technical capability and strategic foresight.
  • Diversification: Avoid over-reliance on single open source projects for critical infrastructure, where possible, to mitigate risks associated with sudden licensing shifts.
  1. Enhancing CISO Resilience and Communication: The "Confessions of a CISO" segment highlighted the immense pressures on security leaders. Defenders should:
  • Develop Crisis Communication Plans: Prepare for high-stakes scenarios like board meetings or regulatory inquiries by having clear, concise communication strategies. Understand the different stakeholders (CEO, board secretaries, PR) and tailor messaging accordingly.
  • Proactive Engagement: Push for early involvement in critical business decisions like M&A or cloud migrations to conduct risk assessments before commitments are made. This prevents being blindsided and allows for proactive security integration.
  • Personal Resilience: Acknowledge the psychological toll of the role and develop coping mechanisms to "stay cool under pressure," even if it means having a "scream room" or a "padded closet" for private stress release.
  1. Optimizing Cybersecurity Hiring and Talent Acquisition: To address "what's broken" in hiring, organizations should:
  • Design Effective Interview Questions: Move beyond trivia. Craft open-ended questions that assess critical thinking, problem-solving, and the ability to articulate complex ideas. Use "what's worse" scenarios to gauge risk management acumen and reasoning.
  • Standardize for Comparison, Customize for Depth: While asking consistent questions aids comparison, interviewers should be prepared to delve deeper based on a candidate's experience level, allowing senior candidates to elaborate on their expertise.
  • Empower Interviewees: Create an environment where candidates feel comfortable expanding on answers, even to poorly phrased questions, to showcase their full capabilities.
  1. Demanding Business Value from Security Vendors: CISOs must shift the narrative in vendor engagements:
  • "Sell More Jeans" Mentality: Challenge sales teams to articulate how their product directly contributes to core business objectives: protecting the brand, people, and supply chain, or making the security team more efficient and effective at stopping attacks.
  • Pre-Sales Research and Technical Depth: Sales teams should conduct thorough research on the prospective client's business and potential security challenges. They must be prepared to bring in sales engineers or security architects early in the process to provide the necessary technical depth and tailored solutions.
  • Avoid "Clueless" Vendors: Be prepared to "write off" vendors whose sales teams demonstrate a fundamental lack of understanding of the client's business or the technical relevance of their product.
  1. Strengthening Supply Chain and Attack Surface Security:
  • Comprehensive Supply Chain Security: Implement solutions (like those offered by Eclypsium) that provide visibility and security for critical software, firmware, and hardware across the entire supply chain. Understand the link between ransomware and supply chain vulnerabilities.
  • Continuous Attack Surface Management: Adopt solutions (like NetSpy's) for continuous discovery and monitoring of known and unknown assets beyond periodic penetration tests. This provides real-time visibility into the expanding attack surface.
  • Embrace SBOMs (Strategically): While operationalizing SBOMs is a "slow journey," organizations should begin to demand and integrate them from key suppliers. Recognize their aspirational value for risk management and prepare for the technical challenges of managing "Turtles all the way down" dependencies.
  1. Leveraging Integrated Security Operations Platforms:
  • Consolidated Platforms: Utilize integrated platforms (like Dvo's) that combine SIM, SOAR, and UEBA with AI and intelligent automation. This enables faster threat detection, automated response, and smarter security operations by reducing noise and correlating disparate data points.
  1. Prioritizing People-Centric Security:
  • Social Engineering Defense: Recognize that "people are the weakest link" and social engineering attacks are a primary vector. Invest in robust security awareness training, phishing simulations, and cultural initiatives to strengthen the human firewall.

By integrating these defensive implications, organizations can build more resilient security programs, foster better internal and external relationships, and more effectively protect their assets against an evolving threat landscape.

Key Takeaways

  • Open Source Licensing is Evolving: Organizations must be vigilant about changes in open source licensing (e.g., Redis, Elastic), understanding the implications for usage, modification, and commercialization. Legal and third-party risk assessments are crucial, and companies should be prepared to license or fork critical components.
  • CISO Resilience is Paramount: Cybersecurity leaders face intense pressure from unexpected board meetings, unconsulted business decisions (M&A, cloud changes), and regulatory scrutiny. Developing strong crisis communication skills, proactive engagement with business units, and personal coping mechanisms are essential for navigating these challenges.
  • Effective Hiring Demands Critical Thinking: The industry needs to move beyond trivia questions in interviews. Hiring managers should craft open-ended questions that assess critical thinking, problem-solving, and the ability to articulate reasoning, rather than just rote knowledge. Interviewees should leverage opportunities to expand on answers and showcase their expertise.
  • Security Sales Must Demonstrate Business Value: Sales teams must deeply understand a client's business and clearly articulate how their security solution protects the brand, people, and supply chain, or enhances the security team's efficiency and effectiveness. Generic pitches are no longer acceptable, and technical experts should be involved early.
  • Continuous Visibility and Supply Chain Integrity are Critical: Modern defense requires continuous attack surface management to identify known and unknown assets, moving beyond periodic pentests. Robust supply chain security for software, firmware, and hardware is vital, with SBOMs representing an aspirational but necessary tool for future risk management.
  • Integrated Security Operations and People-Centric Defense: Leveraging platforms that integrate SIM, SOAR, and UEBA with AI and automation can significantly enhance security operations. Simultaneously, recognizing that "people are the weakest link," organizations must prioritize defenses against social engineering attacks through training and cultural initiatives.

About the Speaker(s)

David Spark is the host and producer of the CISO Series podcast, a media network dedicated to cybersecurity professionals. He is known for his engaging and often humorous approach to discussing complex cybersecurity topics, aiming to make the field more accessible and enjoyable.

Mike Johnson serves as a co-host for the CISO Series podcast, a role he has held for nearly six years. Beyond his podcasting duties, Mike is the CEO of Rivian, bringing a unique perspective on cybersecurity challenges from a leadership position within a major enterprise. He emphasizes the importance of maintaining composure under pressure and effectively managing crises.

Steve Zooki is a guest on the CISO Series podcast and the host of another show, "Defense and Depth." With extensive experience as a CISO, including a notable tenure at Levi Strauss, Steve is recognized for his insights into the political realities of cybersecurity, the strategic importance of demonstrating business value, and his commitment to mentoring and "paying it forward" within the security community.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This live podcast, featuring seasoned CISOs, offered a candid look at strategic cybersecurity challenges, from the evolving landscape of open-source licensing and the practical hurdles of S-BOM implementation to the critical need for security to align with business objectives. While lacking the deep technical dives into exploits I typically seek, the discussion provided valuable, real-world insights into the operational and governance complexities faced by security leaders, offering a pragmatic perspective often missing from purely technical presentations.

Heather Calloway (CISO) — MUST SEE

This live CISO Series podcast delivered an exceptionally relevant and candid discussion on the institutional realities of cybersecurity. The speakers, drawing from deep operational experience, provided invaluable insights into navigating complex issues like open-source licensing shifts, the practical challenges of S-BOM implementation, and the critical need to align security initiatives with core business objectives. This session is a must-see for any security leader seeking to translate technical risk into executive action and drive meaningful organizational change.

→ Top-rated talks at BSidesSF 2024

All talks from BSidesSF 2024