Перейти к содержимому

Episode 49: Show Me What Risk You're Buying Down

Zero Trust Journey

0:00 / 0:00

Episode 49: Show Me What Risk You're Buying Down

18 просмотров · 2 недели назад
Zero Trust Journey
90 подписчиков
18 просмотров · 2 недели назад
00:00 Intro 01:23 Accounting to pen testing to the CISO chair 03:51 Zero to FedRAMP Moderate in six months 06:34 AI and GRC: does the internal auditor disappear? 09:25 The hidden cost of AI adoption 10:49 Fractional CISO: what actually matters first 12:15 The risk register test 13:00 Day one with no security program 14:19 Close Most CISOs cannot draw a line from what they spend to the risk it reduces. Jake Bernardes, CISO, thinks that is the core failure of the role. In this episode of Zero Trust Journey, Jake lays out how he triages a security program: what is actually on fire, what is blocking the business from selling, and what risk every dollar is buying down. Everything else is noise. 🔹 The chartered accountant who became a pen tester who became a CISO 🔹 Why financial literacy is the skill most security leaders are missing 🔹 Every tool, service, and headcount: show me the risk it buys down 🔹 The AI and GRC question nobody answers honestly: is internal audit going away? 🔹 The tuning tax, the hours you spend teaching AI to do the job 🔹 Zero to FedRAMP Moderate in six months, with almost no budget and almost no team 🔹 Day one advice for a first-time CISO walking into zero program