logo
episode-header-image
Aug 2024
30m 17s

Cyber Security vs Frameworks

Dr. Eric Cole
About this episode

In the latest episode of Life of a CISO, Dr. Eric Cole dives deep into the critical difference between compliance and true cybersecurity. He emphasizes that while frameworks and compliance standards are essential, they often focus on checking boxes rather than addressing the holistic needs of a secure environment. Without a strong foundation in cybersecurity, organizations risk having significant gaps in their defenses, leaving them vulnerable to breaches even if they are technically compliant. Dr. Cole illustrates this with real-world examples, underscoring the importance of mastering the basics before layering on complex frameworks.

Dr. Cole also explores the common pitfalls companies face when they rush into implementing frameworks without first securing their critical data and understanding their risk tolerance. He warns against the dangers of overcomplicating compliance efforts, advocating instead for a targeted approach that focuses on the most sensitive areas of the business. By controlling where critical data is stored and minimizing unnecessary exposure, organizations can achieve both compliance and security without overwhelming their resources. This episode is a must-listen for current and aspiring CISOs who want to build a secure, resilient organization from the ground up.

 

Up next
Oct 2
Satellite Communications, AI, and the Future of Secure Connectivity with Guest Brett Miller
In this episode of Life of a CISO, Dr. Eric Cole sits down with Brett Miller, a Marine Corps veteran, former Hollywood creative, and now a leader at Galileo, a cutting-edge satellite communications company. Together, they explore the critical role of secure communications in cybe ... Show More
35m 30s
Sep 25
The Journey to Becoming a CISO: Lessons Learned with Azunna Anyanwu
In this episode of Life of a CISO, Dr. Eric Cole interviews Azunna Anyanwu, a fractional CIO, discussing his career journey, the importance of soft skills in cybersecurity leadership, and the challenges of managing budgets and risk. They delve into the complexities of ransomware, ... Show More
35m 20s
Sep 18
Cybersecurity, AI, and Communication: Dr. Eric Cole with Dr. Jill Schiefelbein
In this episode of Life of a CISO, Dr. Eric Cole sits down with communication strategist and tech-human behavior expert Dr. Jill Schiefelbein. Together, they explore the critical intersection of cybersecurity, leadership, and communication—diving into why technical solutions alon ... Show More
35m 32s
Recommended Episodes
Oct 2024
Navigating NIST CSF 2.0: Guide to Frameworks and Governance
In this episode, we sat down with Lukasz Gogolkiewicz, an Australia-based Cybersecurity Leader and former pentester, to explore his journey from offensive security into cybersecurity leadership. Lukasz, also a speaker coach at BlackHat USA, brings valuable insights into what it t ... Show More
36m 29s
Oct 2024
Balancing Security with Usability in Cybersecurity
In this episode of Threat Vector, host David Moulton talks with guest speaker Brian Wrozek, Forrester Principal Analyst in Security & Risk, about the complexities of aligning security strategies across global teams. Brian draws on his extensive experience in cybersecurity, operat ... Show More
41m 41s
Dec 2024
Behind the Scenes with Palo Alto Networks CIO and CISO Securing Business Success with Frictionless Cybersecurity
In this episode of Threat Vector, David Moulton speaks with Meerah Rajavel, CIO of Palo Alto Networks, and Niall Browne, CISO of the organization, about the importance of aligning IT strategy with cybersecurity.  Meerah and Niall discuss how frictionless security, AI integration, ... Show More
39m 17s
Mar 2025
Understanding Insider Threats With Eran Barak, CEO of MIND: Cyber Security Today for March 8, 2025
Understanding Insider Threats in Cybersecurity with Eran Barak Join host Jim Love as he discusses the critical issue of insider threats in cybersecurity with Eran Barak, CEO of MIND, a data security firm. In this episode, they explore the various types of insider threats, from in ... Show More
35m 49s
Feb 2025
Rethinking Cloud Security Strategies
Cloud security is more complex than ever. Organizations move fast, but security teams often struggle to keep up. In this episode of Threat Vector, host David Moulton speaks with Amol Mathur, SVP of Products for Prisma Cloud at Palo Alto Networks, about how platformization is resh ... Show More
35m 28s
Apr 2025
Understanding SaaS Security: Insights, Challenges, and Best Practices
In this episode of Cybersecurity Today, host Jim Love delves into the topic of SaaS (Software as a Service) security. Sharing his early experiences promoting SaaS, Jim elaborates on its inevitable rise due to cost-effectiveness and shared development resources. The episode highli ... Show More
38m 5s
Jun 2025
Vibe Coding vs Low-Code/No-Code: Security Risks and CI/CD Pipeline Impacts for Citizen Developers
Explore the evolution from traditional coding to vibe coding and its relationship with low-code/no-code (LCNC) platforms. This comprehensive analysis examines how AI-assisted development and visual programming tools are creating a new generation of citizen developers, transformin ... Show More
9m 42s
Oct 2024
Leadership during a Crisis
In this insightful episode of Threat Vector, host David Moulton sits down with Christopher Scott, Managing Partner at Unit 42 by Palo Alto Networks, to explore the essentials of crisis leadership and management in cybersecurity. With over two decades of experience, Chris shares h ... Show More
35m 40s
Nov 2024
War Room Best Practices
In this episode of Threat Vector, David Moulton, Director of Thought Leadership at Unit 42, is joined by cybersecurity experts Kyle Wilhoit, Director of Threat Research, and Michal Goldstein, Director of Security Architecture and Research at Palo Alto Networks. Together, they exp ... Show More
35m 17s
Apr 2025
Cybersecurity Today: Virtual Employees, AI Security Agents, and CVE Program Updates
In this episode of 'Cybersecurity Today,' host Jim Love discusses various pressing topics in the realm of cybersecurity. Highlights include Anthropic's prediction on AI-powered virtual employees and their potential security risks, Microsoft’s introduction of AI security agents to ... Show More
7m 47s