Defense in Depth
Defense in Depth
Defense in Depth·Jul 30, 2026·30m

Why is Preventative Security So Difficult?

Show notes

All links and images can be found on CISO Series

Prevention in cybersecurity is a lot like flossing: everyone knows they should do it, but few do it enough. What's stopping us?

Check out this post by Ross Haleliuk of Venture in Security for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Deneen DeFiore, vice president & chief information security officer, United Airlines.

In this episode:

  • The sponsorship gap
  • One strike and you're out
  • Policy without position
  • Prevention isn't static

A huge thanks to our sponsor, CoreView

Attackers don't break into Microsoft 365. They log in and reconfigure it. When tenant configurations drift or get tampered with, recovery can take weeks and missed settings can reopen the door. The Cyber Resilience Framework for Microsoft 365 covers the five pillars, harden, govern, detect, respond, recover, and shows exactly where today's tools leave gaps. Download the free practical guide