
VCISO Tradecraft | Carlota Sage - #298
Show notes
Most cybersecurity advice is built for massive enterprises.
But what happens when you're a small or medium-sized business and you don't have a 200-person security team… or a massive budget?
In this episode, Mark Hardy sits down with vCISO Carlota Sage to break down what actually works.
Carlota shares lessons from her time at FireEye during its explosive growth and the Mandiant acquisition—and why being a great security leader isn't just about knowing cybersecurity.
It's about IT fundamentals. Influence. Emotional intelligence. And knowing how to lead people.
We also dive into:
Why simply saying "thank you" can transform your security culture 💰 How cybersecurity can become sales enablement and revenue protection 📈 Why security teams should work directly with sales and finance 🔒 Why compliance isn't security—but ISO 27001 and PCI DSS can still be incredibly valuable for smaller companies 🤖 How AI is creating a massive new attack surface 🕵️ The growing risk of sensitive data leaking into AI tools 💸 Why the real cost of AI isn't just the subscription price 🎯 Who should be accountable when AI goes wrong
The BIG takeaway?
You don't need to be a Fortune 500 company to build a strong security program.
But you do need to understand the business, influence people, protect revenue, and help your organization use technology without creating a disaster in the process.
Watch now and let us know in the comments:
What's the biggest cybersecurity challenge facing small and medium-sized businesses right now? 👇