CISO Tradecraft®
by G Mark Hardy & Ross Young
You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level.
© Copyright 2025, National Security Corporation. All Rights Reserved
© Copyright 2025, National Security Corporation. All Rights Reserved
Sep 14, 2026Recent reviews on Apple Podcasts (4)
So informative and logically organized
This podcast has been instrumental in transforming how I think about cyber and business risk. There’s not a lot of other podcasts that I’ve seen or heard from that enables you to go wider or deeper in your understanding. Thank you for the effort y’all put into these and what you’re doing for our community.
JoshSommers ·
Critical Information for Our Critical Infrastructure
The nature of the internet makes it incumbent on every organization to prevent intrusions, be they foreign or domestic. Corporate cybersecurity is not a business concern. It is a national Security concern. For this reason, the information conveyed in this podcast should be on every cybersecurity professional’s listening list , from CISO to entry level security associateS just beginning their career. There is no unimportant person when it comes to cybersecurity. Anyone who uses a computer connected to the internet can reign down catastrophe on an organization. It is up to cybersecurity personnel to prevent that from happening. G. Mark Hardy seems almost chosen to be the one that helps corporations stay safe. It doesn’t hurt that he has a calm, reassuring, voice that conveys a message that this is doable, and that you are the one who can do it.
PBinNewJ ·
A great resource for those in the cyber world
This is such a great casual podcast for those looking to work their way into management in the cyber world. I recommend this to anyone who is interested!!
idavis7 ·
Really interesting podcast for people wanting to be a CISO
There are a lot of podcasts on cyber security. This one has something unique. The creators have a natural energy that resonates well and I enjoy their thoughts. What is most impressive is learning how to become a ciso. There is no silver bullet but the points they bring up are really interesting. I look forward to hearing more episodes
Financialadventure ·
Episodes (301)

How to Create a Leadership Culture - #301
Sep 14, 202643m#301
Most CISOs spend years learning cybersecurity. Almost nobody teaches them how to build a culture people actually want to be part of. In this episode of CISO Tradecraft, G. Mark Hardy and Ross Young break down the leaders

CISO Health and Accountability Dialogue - #300
Sep 7, 202615m#300
The biggest threat to a CISO might not be ransomware, it might be burnout. In this episode, G. Mark Hardy brings on We Hack Health to reveal why brilliant security leaders are sacrificing their health, how accountability

Claude Code Is INSANE, But Is It Safe? - #299
Aug 31, 202645m#299
Claude Code Is INSANE… But Is It Safe? AI coding just went from “autocomplete my code” to “give me the entire repository and let me run the company.” In this episode of CISO Tradecraft , G Mark Hardy and Ross Young break

VCISO Tradecraft | Carlota Sage - #298
Aug 25, 202642m#298
Most cybersecurity advice is built for massive enterprises. But what happens when you're a small or medium-sized business and you don't have a 200-person security team… or a massive budget? In this episode, Mark Hardy si

AI's Biggest Security Problem | Jeff Spear - #297
Aug 17, 202640m#297
AI can change your network in seconds… but your security approvals still take DAYS. In this episode, Tufin CISO Jeffrey Spear reveals how CISOs can use automation and AI without accidentally scaling security mistakes at

AI Is Breaking Out and Cybersecurity Isn’t Ready | John Strand - #296
Aug 10, 202644m#296
What happens when AI stops behaving like a tool, and starts operating beyond the boundaries we gave it? Live from Black Hat, G Mark Hardy sits down with cybersecurity veteran John Strand of Black Hills Information Securi

Is AI Leaking Your Company's Trade Secrets | Lee Kim - #295
Aug 3, 202645m#295
What Every CISO Needs to Know Before AI Leaks Your Company's Crown Jewels Your AI policy won't save you if your trade secrets walk out the door. In this episode of CISO Tradecraft, attorney and technologist Lee Kim expla

Learning from the Hugging Face Incident | Gadi Evron - #294
Jul 27, 202648m#294
In this CISO Tradecraft episode, host G Mark Hardy and guest Gadi Evron discuss a recent incident involving OpenAI model testing in an “exploit gym,” where an agent escaped its sandbox, attempted to access Hugging Face,

Legal Developments Every CISO Needs to Know | Larry Dietz - #293
Jul 20, 202641m#293
Three major legal changes. One question every CISO should be asking: Is your cybersecurity program ready? Congress let a key FISA surveillance authority expire. The Supreme Court raised the bar on geofence warrants. The

The Business Risk Playbook CISOs Use to Win - #292
Jul 13, 202641m#292
What separates great CISOs from everyone else? It isn't knowing more about CVEs, ransomware, or the latest security tools. It's understanding the business. In this episode of CISO Tradecraft, Ross Young and G Mark Hardy

The CISO Mind Map Has Evolved for the AI Era - #291
Jul 6, 202641m#291
How has the role of the CISO changed over the last 15 years? In this episode of CISO Tradecraft, G. Mark Hardy interviews Rafeeq Rehman, creator of the CISO Mind Map, to discuss its latest update and the biggest challeng

Harvest Now, Decrypt Later | Marcus Sachs - #290
Jun 29, 202641m#290
Nation-state adversaries are vacuuming up encrypted traffic today, waiting for quantum computers to decrypt it tomorrow. This attack strategy, "Harvest Now, Decrypt Later," isn't theoretical. It's happening right now. G

#289 - What's the Best Career Move After Being a CISO? (with Gary Hayslip)
Jun 22, 202643m#289
On this episode of CISO Tradecraft, host G Mark Hardy talks with Gary Hayslip about cybersecurity career growth beyond the traditional CISO “apex,” drawing on Hayslip’s 25+ years across military service, US Navy civil se

#288 - How to Break Into Cybersecurity Through GRC (with Steve McMichael)
Jun 15, 202639m#288
In this CISO Tradecraft episode, host G Mark Hardy interviews Steve McMichael, author of "How to Break into GRC: Mindset, Methods, and Skills," about entering cybersecurity through governance, risk, and compliance. McMic

#287 - Cybersecurity Insights You'll Want to Hear (with Michael Hammer)
Jun 8, 202645m#287
Want to move from "security expert" to "trusted business leader"? Join G. Mark Hardy and Michael Hammer. The mind behind the core of DMARC , for 40 years of hard-won wisdom on navigating the CISO role, This episode is a

#286 - AI-Native Security (with Nishant Doshi & Saro Subbiah)
Jun 1, 202645m#286
What if your next breach isn't caused by a human... but by an AI agent acting exactly as instructed? Cyberhaven's CEO (Nishant Doshi) and SVP of Engineering (Saro Subbiah) reveal why AI is a true zero-to-one shift, why e

#285 - Passwordless Authentication (with Nishant Kaushik)
May 25, 202642m#285
In this discussion, G. Mark Hardy and Nishant Kaushik explore the necessity of moving beyond traditional passwords, which they define as the original sin of cybersecurity due to their vulnerability to credential stuffing

#284 - Lessons Learned from SQL Slammer to AI Agents (with Aaron Turner)
May 18, 202645m#284
What can today’s CISOs learn from the chaos of Code Red and SQL Slammer? In this episode, G Mark Hardy interviews Aaron Turner about what it was like responding inside Microsoft during two of the most infamous cyber outb

#283 - Leadership Lessons and the Art of the Performance (with Chris Brogan)
May 11, 202647m#283
In this episode of the CISO Tradecraft podcast, host G Mark Hardy interviews early tech adopter Chris Brogan to explore the intersection of high-performance leadership and effective communication. Drawing from his interv

#282 - Top 10 Agentic AI Attacks (with Rock Lambros)
May 4, 202645m#282
In this CISO Tradecraft episode, host G Mark Hardy interviews recovering CISO Rock Lambros (Zenity) about securing Agentic AI and the emerging risks beyond LLM hallucinations. Lambros recounts his path from Oracle develo

#281 - SIEM Secrets They Don’t Tell You (with Anton Chuvakin & Alex Hurtado)
Apr 27, 202648m#281
In this CISO Tradecraft episode, host G Mark Hardy talks with Anton Chuvakin and Alex Hurtado about how SIEM programs fail and how organizations overspend when implementations prioritize dashboards or compliance over act

#280 - Mythos and the Future of Vulnerability Operations (with Gadi Evron)
Apr 20, 202643m#280
In this episode of CISO Tradecraft, host G Mark Hardy speaks with Gadi Evron about the paper “The AI Vulnerability Storm Building: A Mythos Ready Security Program,” a community-driven draft produced in days with extensiv

#279 - AI Readiness (with JP Bourget)
Apr 13, 202644m#279
On CISO Tradecraft, host G Mark Hardy welcomes back JP Bourgeet to discuss what “AI readiness” means for organizations, framing it as both a data governance challenge and a change-management problem. JP defines readiness

#278 - RSAC Takeaways: AI SOC, Agent Security, and What Cyber Marketing Gets Wrong
Apr 7, 202645m#278
In this CISO Tradecraft episode, G Mark Hardy, Ross Young, and Andy Ellis share RSAC insights from the vendor floor, including Andy’s effort to visit about 607 booths. They highlight dominant themes like AI SOC offerings

#277 - From SaaS to AI Agents: Gone in 60 Seconds
Mar 30, 202639m#277
In this CISO Tradecraft episode, co-hosts G Mark Hardy and Ross Young discuss how large language models are transforming software development and shifting cybersecurity from buying Software as a Service to “Service as So